A transformation approach for security enhanced business processes

  • Authors:
  • Christian Wolter;Andreas Schaad;Christoph Meinel

  • Affiliations:
  • SAP Research, Karlsruhe, Germany;SAP Research, Karlsruhe, Germany;University of Potsdam, Potsdam, Germany

  • Venue:
  • SE '08 Proceedings of the IASTED International Conference on Software Engineering
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

The Business Process Modeling Notation (BPMN) has become the defacto standard for describing processes in an accessible graphical notation. The eXtensible Access Control Markup Language (XACML) and WS-Security are both OASIS standards used to specify and enforce platform independent access control and security policies suitable for service-oriented architectures. In this document we propose a transformation approach based on a security modeling framework for business process management to support access control and security policies for business processes. To deploy and enforce such security policies in an enterprise environment, a model-driven transformation between security annotated process models and a security specification language is used. We argue that specific types of organisational control and compliance policies may be expressed in a graphical fashion at the business process modeling level. These can then be transformed into corresponding access control and security policies for business process-driven information systems based on service-oriented architectures. This approach acts as an enabler for better collaboration between security and business process domain experts to define consistent and valid security policies that can be easily communicated. We discuss the benefits of our modeling approach and outline how our framework can support security and compliance in business processes.