Conformance checking of electronic business processes to secure distributed transactions

被引:0
|
作者
Talamo, Maurizio [1 ]
Arcieri, Franco [2 ]
Schunck, Christian H. [2 ]
D'Iddio, Andrea Callia [1 ]
机构
[1] Univ Roma Tor Vergata, Dept Business Engn, I-00133 Rome, Italy
[2] Univ Roma Tor Vergata, Nestor Lab, I-00133 Rome, Italy
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Advances in computer technologies facilitate the implementation of inter-organizational business processes. At the same time, managing the security of these processes is increasingly difficult. Compliance with high level specifcations, like normatives and pre-agreed protocols, rules and requirements, is difficult to validate. Here we discuss how Conformance Checking, a specific area of Process Mining, can be adapted for this purpose. Its role is to verify if an execution of a business process satisfies specifications represented by formal models (e.g. Petri Nets, Transition Systems, structures based on partial orders, etc). In the process mining literature, few efforts have been dedicated to online checking of business processes and choreographies for security purposes. The main requirement is high precision and reliability of event logs. They should record, precisely and unambiguously, all security-relevant activities of the analyzed process. Mantaining high-level logs becomes difficult with choreographies: log data are distributed, and must be related to events. Important metadata of event logs, like timestamps, can be ambiguous. Moreover, some data cannot be distributed due to security or privacy issues. These problems result in security-relevant ambiguities in event logs. Here we define a framework to create high-level event logs for online inter-organizational compliance checking using a Validation Authority. The system described here has been implemented in the issuing infrastructure for the Italian Electronic Identity card.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Complete and Interpretable Conformance Checking of Business Processes
    Garcia-Banuelos, Luciano
    van Beest, Nick R. T. P.
    Dumas, Marlon
    La Rosa, Marcello
    Mertens, Willem
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2018, 44 (03) : 262 - 290
  • [2] Fuzzy multi-perspective conformance checking for business processes
    Zhang, Sicui
    Genga, Laura
    Dekker, Lukas
    Nie, Hongchao
    Lu, Xudong
    Duan, Huilong
    Kaymak, Uzay
    [J]. APPLIED SOFT COMPUTING, 2022, 130
  • [3] A CSP-theoretic framework of checking conformance of Business Processes
    Roy, Suman
    Bihary, Sidharth
    Laos, Jose Alfonso Corso
    [J]. 2012 19TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE (APSEC), VOL 1, 2012, : 30 - 39
  • [4] Data- and Resource-Aware Conformance Checking of Business Processes
    de Leoni, Massimiliano
    van der Aalst, Wil M. P.
    van Dongen, Boudewijn F.
    [J]. BUSINESS INFORMATION SYSTEMS, BIS 2012, 2012, 117 : 48 - 59
  • [5] Design methodology for secure distributed transactions in electronic commerce
    Portillo, E
    Patel, A
    [J]. COMPUTER STANDARDS & INTERFACES, 1999, 21 (01) : 5 - 18
  • [6] Distributed Process Discovery and Conformance Checking
    van der Aalst, Wil M. P.
    [J]. FUNDAMENTAL APPROACHES TO SOFTWARE ENGINEERING, FASE 2012, 2012, 7212 : 1 - 25
  • [7] A Conformance Checking-Based Approach for Sudden Drift Detection in Business Processes
    Gallego-Fontenla, Victor
    Vidal, Juan C.
    Lama, Manuel
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2023, 16 (01) : 13 - 26
  • [8] Conformance Checking: Relating Processes and Models
    Carmona, Josep
    van Dongen, Boudewijn
    Weidlich, Matthias
    [J]. ADVANCED INFORMATION SYSTEMS ENGINEERING (CAISE 2019), 2019, 11483 : 700 - 700
  • [9] Checking conformance between business processes and web service contract in service oriented applications
    Bhuiyan, Jenny
    Nepal, Surya
    Zic, John
    [J]. 2006 AUSTRALIAN SOFTWARE ENGINEERING CONFERENCE, PROCEEDINGS, 2006, : 80 - +
  • [10] Automatic support for verification of secure transactions in distributed environment using symbolic model checking
    Di Sciascio, E
    Donini, FM
    Mongiello, M
    Piscitelli, G
    [J]. ITI 2001: PROCEEDINGS OF THE 23RD INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY INTERFACES, 2001, : 447 - 454