An XACML extension for business process-centric access control policies

  • Authors:
  • Christian Wolter;Christian Weiß;Christoph Meinel

  • Affiliations:
  • SAP Research CEC Karlsruhe, Karlsruhe, Gennany;SAP Research CEC Karlsruhe, Karlsruhe, Gennany;Hasso-Plattner-Institute, University of Potsdam, Gennany

  • Venue:
  • POLICY'09 Proceedings of the 10th IEEE international conference on Policies for distributed systems and networks
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Administrative controls exist to ensure that business activities are correctly managed and controlled according to corporate and legal regulations. With many organisations reliant on complex IT solutions these controls relate to functionality of software. In this paper we present an extension for business process models to express administrative controls, such as role-based, mandatory or dynamic separation of duty access control policies on the abstraction level of business process models. A model-driven approach is applied to generate platform-specific policies. As an example we utilise the eXtensible Access Control Markup Language (XACML).