Possibilistic Information Flow Control for Workflow Management Systems

被引:0
|
作者
Bauereiss, Thomas [1 ]
Hutter, Dieter [1 ]
机构
[1] German Res Ctr Artificial Intelligence DFKI, Bibliothekstr 1, D-28359 Bremen, Germany
关键词
D O I
10.4204/EPTCS.148.4
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In workflows and business processes, there are often security requirements on both the data, i.e. confidentiality and integrity, and the process, e.g. separation of duty. Graphical notations exist for specifying both workflows and associated security requirements. We present an approach for formally verifying that a workflow satisfies such security requirements. For this purpose, we define the semantics of a workflow as a state-event system and formalise security properties in a trace-based way, i.e. on an abstract level without depending on details of enforcement mechanisms such as Role-Based Access Control (RBAC). This formal model then allows us to build upon well-known verification techniques for information flow control. We describe how a compositional verification methodology for possibilistic information flow can be adapted to verify that a specification of a distributed workflow management system satisfies security requirements on both data and processes.
引用
收藏
页码:47 / 62
页数:16
相关论文
共 50 条
  • [21] Information Flow for Security in Control Systems
    Weerakkody, Sean
    Sinopoli, Bruno
    Kar, Soummya
    Datta, Anupam
    [J]. 2016 IEEE 55TH CONFERENCE ON DECISION AND CONTROL (CDC), 2016, : 5065 - 5072
  • [22] INFORMATION-SYSTEMS FOR MANAGEMENT CONTROL
    PRINCE, TR
    [J]. ACCOUNTING REVIEW, 1964, 39 (02): : 467 - 472
  • [23] Project management information control systems
    Shahid, S
    Froese, T
    [J]. CANADIAN JOURNAL OF CIVIL ENGINEERING, 1998, 25 (04) : 735 - 754
  • [24] Information Flow in Maritime Safety Management Systems
    Grabon-Chalupczak, M.
    [J]. TRANSNAV-INTERNATIONAL JOURNAL ON MARINE NAVIGATION AND SAFETY OF SEA TRANSPORTATION, 2020, 14 (03) : 637 - 640
  • [25] Control and Management of Coal Mines with Control Information Systems
    Grozdanovic, Miroljub
    Marjanovic, Dobrivoje
    Janackovic, Goran
    [J]. INTERNATIONAL ARAB JOURNAL OF INFORMATION TECHNOLOGY, 2016, 13 (04) : 387 - 395
  • [26] Using Laboratory Information Management Systems as central part of a proteomics data workflow
    Stephan, Christian
    Kohl, Michael
    Turewicz, Michael
    Podwojski, Katharina
    Meyer, Helmut E.
    Eisenacher, Martin
    [J]. PROTEOMICS, 2010, 10 (06) : 1230 - 1249
  • [27] Workflow management systems - Introduction
    Rusinkiewicz, M
    Helal, S
    [J]. JOURNAL OF INTELLIGENT INFORMATION SYSTEMS, 1998, 10 (02) : 91 - 92
  • [28] Time management in workflow systems
    Eder, J
    Panagos, E
    Pozewaunig, H
    Rabinovich, M
    [J]. BIS'99: 3RD INTERNATIONAL CONFERENCE ON BUSINESS INFORMATION SYSTEMS, 1999, : 265 - 280
  • [29] Evaluating workflow management systems
    Berger, M
    Ellmer, E
    Quirchmayr, G
    Zeitlinger, A
    [J]. EIGHTH INTERNATIONAL WORKSHOP ON DATABASE AND EXPERT SYSTEMS APPLICATIONS, PROCEEDINGS, 1997, : 412 - 417
  • [30] The application of role-based access control in workflow management systems
    Liu, JX
    Sun, LX
    [J]. 2004 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN & CYBERNETICS, VOLS 1-7, 2004, : 5492 - 5496