Conformance Checking of RBAC Policies in Process-Aware Information Systems

被引:0
|
作者
Baumgrass, Anne [1 ]
Baier, Thomas [2 ]
Mendling, Jan [2 ]
Strembeck, Mark [1 ]
机构
[1] Vienna Univ Econ & Business WU Vienna, Inst Informat Syst & New Media, Vienna, Austria
[2] Humboldt Univ, Inst Informat Syst, Berlin, Germany
关键词
Process-Aware Information Systems; Conformance Checking; LTL; Security; Role-Based Access Control;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A process-aware information system (PAIS) is a software system that supports the definition, execution, and analysis of business processes. The execution of process instances is typically recorded in so called event logs. In this paper, we present an approach to automatically generate LTL (Linear Temporal Logic) statements from process-related RBAC (Role-based Access Control) models. These LTL statements are used to check if process executions that are recorded via event logs conform to the access control policies defined via a corresponding RBAC model. To demonstrate our approach, we implemented a RBAC-to-LTL component, and used the ProM tool to test the resulting LTL statements with event logs created from process simulations in CPN tools.
引用
收藏
页码:435 / +
页数:3
相关论文
共 50 条
  • [1] Model-driven specification and enforcement of RBAC break-glass policies for process-aware information systems
    Schefer-Wenzl, Sigrid
    Strembeck, Mark
    [J]. INFORMATION AND SOFTWARE TECHNOLOGY, 2014, 56 (10) : 1289 - 1308
  • [2] Time patterns for process-aware information systems
    Andreas Lanz
    Barbara Weber
    Manfred Reichert
    [J]. Requirements Engineering, 2014, 19 : 113 - 141
  • [3] Process-Aware Information Systems for Emergency Management
    de Leoni, Massimiliano
    Marrella, Andrea
    Russo, Alessandro
    [J]. TOWARDS A SERVICE-BASED INTERNET: SERVICEWAVE 2010 WORKSHOPS, 2011, 6569 : 50 - +
  • [4] Time patterns for process-aware information systems
    Lanz, Andreas
    Weber, Barbara
    Reichert, Manfred
    [J]. REQUIREMENTS ENGINEERING, 2014, 19 (02) : 113 - 141
  • [5] Patterns for Process Edification in Process-aware Information Systems
    Yadav, Vrinda
    Roy, Suman
    Joshi, Rushikesh K.
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING (IEEE SCC 2018), 2018, : 161 - 168
  • [6] Mining and Simulation for Process-Aware Information Systems
    Brito e Abreu, Fernando
    [J]. ADVANCED INFORMATION SYSTEMS ENGINEERING (CAISE 2022), 2022, : 557 - 559
  • [7] Robust and Reliable Process-Aware Information Systems
    Schwerz, Andre Luis
    Liberato, Rafael
    Pu, Calton
    Ferreira, Joao Eduardo
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2021, 14 (03) : 820 - 833
  • [8] Workflow Time Patterns for Process-Aware Information Systems
    Lanz, Andreas
    Weber, Barbara
    Reichert, Manfred
    [J]. ENTERPRISE, BUSINESS-PROCESS AND INFORMATION SYSTEMS MODELING, 2010, 50 : 94 - +
  • [9] An Approach for Consistent Delegation in Process-Aware Information Systems
    Schefer-Wenzl, Sigrid
    Strembeck, Mark
    Baumgrass, Anne
    [J]. BUSINESS INFORMATION SYSTEMS, BIS 2012, 2012, 117 : 60 - 71
  • [10] On the Modeling and Verification of Security-Aware and Process-Aware Information Systems
    Crampton, Jason
    Huth, Michael
    [J]. BUSINESS PROCESS MANAGEMENT WORKSHOPS, PT II, 2012, 100 : 423 - +