arrow
Return

Model-driven business process security requirement specification

delete2009-04-01
delete67
PRE
AI
C
Christian Wolter *
M
Michael Menzel
A
Andreas Schaad
P
Philip Miseldine
C
Christoph Meinel
DOI:10.1016/j.sysarc.2008.10.002delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Various types of security goals, such as authentication or confidentiality. can be defined as policies for service-oriented architectures, typically in a manual fashion. Therefore, we foster a model-driven transformation approach from modelled security goals in the context of process models to concrete security implementations. We argue that specific types of security goals may be expressed in a graphical fashion at the business process modelling level which in turn can be transformed into corresponding access control and security policies. In this paper we present security policy and policy constraint models. We further discuss a translation of security annotated business processes into platform specific target languages, such as XACML or AXIS2 security configurations. To demonstrate the suitability of this approach an example transformation is presented based on an annotated process. (C) 2008 Elsevier B.V. All rights reserved
Keywords:
Web service security
Business process
Model transformation
Security annotations
Access control
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Journal of Systems Architecture cover
Journal of Systems Architecture
IF:
4.1
Papers:
3.0K
Citations:
4.2K

Organization

S
sap
Scholars:
69
Papers: 70
Citations: 0
U
University of Potsdam
Scholars:
7.8K
Papers: 7.1K
Citations: 1.4W