BP-XACML an Authorisation Policy Language for Business Processes

被引:2
|
作者
Alissa, Khalid [1 ,2 ]
Reid, Jason [1 ]
Dawson, Ed [1 ]
Salim, Farzad [1 ]
机构
[1] Queensland Univ Technol, Inst Future Environm, Brisbane, Qld 4001, Australia
[2] KACST, Riyadh, Saudi Arabia
关键词
XACML; BPM; Workflow; Authorisation management; Authorisation policy language;
D O I
10.1007/978-3-319-19962-7_18
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
XACML has become the defacto standard for enterprisewide, policy-based access control. It is a structured, extensible language that can express and enforce complex access control policies. There have been several efforts to extend XACML to support specific authorisation models, such as the OASIS RBAC profile to support Role Based Access Control. A number of proposals for authorisation models that support business processes and workflow systems have also appeared in the literature. However, there is no published work describing an extension to allow XACML to be used as a policy language with these models. This paper analyses the specific requirements of a policy language to express and enforce business process authorisation policies. It then introduces BP-XACML, a new profile that extends the RBAC profile for XACML so it can support business process authorisation policies. In particular, BP-XACML supports the notion of tasks, and constraints at the level of a task instance, which are important requirements in enforcing business process authorisation policies.
引用
收藏
页码:307 / 325
页数:19
相关论文
共 50 条
  • [1] Usage Control Model Specification in XACML Policy Language XACML Policy Engine of UCON
    Um-e-Ghazia
    Masood, Rahat
    Shibli, Muhammad Awais
    Bilal, Muhammad
    COMPUTER INFORMATION SYSTEMS AND INDUSTRIAL MANAGEMENT (CISIM), 2012, 7564 : 68 - 79
  • [2] XACML Policy Profile for Multidomain Network Resource Provisioning and Supporting Authorisation Infrastructure
    Demchenko, Yuri
    Cristea, Mihai
    de Laat, Cees
    2009 IEEE INTERNATIONAL SYMPOSIUM ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, 2009, : 98 - 101
  • [3] An approach to capture authorisation requirements in business processes
    Wolter, Christian
    Meinel, Christoph
    REQUIREMENTS ENGINEERING, 2010, 15 (04) : 359 - 373
  • [4] An approach to capture authorisation requirements in business processes
    Christian Wolter
    Christoph Meinel
    Requirements Engineering, 2010, 15 : 359 - 373
  • [5] Querying business processes with BP-QL
    Beeri, Catriel
    Eyal, Anat
    Kamenkovich, Simon
    Milo, Tova
    INFORMATION SYSTEMS, 2008, 33 (06) : 477 - 507
  • [6] Language Policy in Business: Discourse, Ideology and Practice
    Brennan, Sara C.
    JOURNAL OF LANGUAGE AND POLITICS, 2021, 20 (06) : 971 - 974
  • [7] Language policy in business: Discourse, ideology and practice
    Wu, Jasper Zhao Zhen
    LANGUAGE IN SOCIETY, 2022, 51 (03) : 546 - 547
  • [8] Language Policy in Business: Discourse, Ideology and Practice
    Burdick, Christa
    JOURNAL OF SOCIOLINGUISTICS, 2022, 26 (02) : 299 - 303
  • [9] Using Large Language Models in Business Processes
    Grisold, Thomas
    vom Brocke, Jan
    Kratsch, Wolfgang
    Mendling, Jan
    Vidgof, Maxim
    BUSINESS PROCESS MANAGEMENT, BPM 2023, 2023, 14159 : XXIX - XXXI
  • [10] Transformational Design of Business Processes in BPEL Language
    Ratkowski, Andrzej
    Zalewski, Andrzej
    Piech, Bartlomiej
    E-INFORMATICA SOFTWARE ENGINEERING JOURNAL, 2009, 3 (01) : 103 - 117