TY - GEN
T1 - Security views for outsourced business processes
AU - Benameur, A.
AU - Massacci, F.
AU - Rassadko, N.
PY - 2008
Y1 - 2008
N2 - The workflow of a Virtual Organization is often divided into fragments that are run by different entities having different clearance level or accessibility permissions. Therefore, an important issue is a decomposition of the overall business process into workflow views that can be outsourced to the side of the corresponding contractors. In this paper, we introduce the notion of business process security view and present an algorithm for the automatic derivation of such views from a security specification that may express conditional accessibility based on the actual data flowing across business process. Our solution borrows the idea of virtual views from relational database views. We also discuss an architecture and an implementation for workflow view synchronization. Copyright 2008 ACM.
AB - The workflow of a Virtual Organization is often divided into fragments that are run by different entities having different clearance level or accessibility permissions. Therefore, an important issue is a decomposition of the overall business process into workflow views that can be outsourced to the side of the corresponding contractors. In this paper, we introduce the notion of business process security view and present an algorithm for the automatic derivation of such views from a security specification that may express conditional accessibility based on the actual data flowing across business process. Our solution borrows the idea of virtual views from relational database views. We also discuss an architecture and an implementation for workflow view synchronization. Copyright 2008 ACM.
U2 - 10.1145/1456492.1456500
DO - 10.1145/1456492.1456500
M3 - Conference contribution
SN - 9781605582924
T3 - Proceedings of the ACM Conference on Computer and Communications Security
SP - 45
EP - 52
BT - Proceedings of the 2008 ACM Workshop on Secure Web Services, SWS'08, Co-located with the 15th ACM Computer and Communications Security Conference, CCS'08
T2 - 2008 ACM Workshop on Secure Web Services, SWS'08, Co-located with the 15th ACM Computer and Communications Security Conference, CCS'08
Y2 - 27 October 2008 through 31 October 2008
ER -