InDico: information flow analysis of business processes for confidentiality requirements

  • Authors:
  • Rafael Accorsi;Claus Wonnemann

  • Affiliations:
  • Department of Telematics, University of Freiburg, Germany;Department of Telematics, University of Freiburg, Germany

  • Venue:
  • STM'10 Proceedings of the 6th international conference on Security and trust management
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper presents InDico, an approach for the automated analysis of business processes against confidentiality requirements. InDico is motivated by the fact that in spite of the correct deployment of access control mechanisms, information leaks in automated business processes can persist due to erroneous process design. InDico employs a meta-model based on Petri nets to formalize and analyze business processes, thereby enabling the identification of leaks caused by a flawed process design.