Generic support for RBAC break-glass policies in process-aware information systems

  • Authors:
  • Sigrid Schefer-Wenzl;Mark Strembeck

  • Affiliations:
  • Institute for Information Systems and New Media, WU Vienna, Austria;Institute for Information Systems and New Media, WU Vienna, Austria

  • Venue:
  • Proceedings of the 28th Annual ACM Symposium on Applied Computing
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

We present a break-glass extension for process-related role-based access control (RBAC) models. Our extension ensures the static (design-time) and dynamic (runtime) consistency of corresponding break-glass models. The extension is generic in the sense that it can, in principle, be used to extend arbitrary process-aware information systems or process modeling languages with support for process-related RBAC and corresponding break-glass policies. We implemented a library and runtime engine that provides full platform support for all properties of our approach.