Formal Specification and Automatic Analysis of Business Processes under Authorization Constraints: An Action-Based Approach

  • Authors:
  • Alessandro Armando;Enrico Giunchiglia;Serena Elisa Ponta

  • Affiliations:
  • DIST --- Università di Genova, Italy;DIST --- Università di Genova, Italy;DIST --- Università di Genova, Italy

  • Venue:
  • TrustBus '09 Proceedings of the 6th International Conference on Trust, Privacy and Security in Digital Business
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

We present an approach to the formal specification and automatic analysis of business processes under authorization constraints based on the action language $\cal{C}$. The use of $\cal{C}$ allows for a natural and concise modeling of the business process and the associated security policy and for the automatic analysis of the resulting specification by using the Causal Calculator (CCALC). Our approach improves upon previous work by greatly simplifying the specification step while retaining the ability to perform a fully automatic analysis. To illustrate the effectiveness of the approach we describe its application to a version of a business process taken from the banking domain and use CCALC to determine resource allocation plans complying with the security policy.