Information flow control for workflow management systems

被引:3
|
作者
Bauereiss, Thomas [1 ]
Hutter, Dieter [1 ]
机构
[1] Deutsch Forschungszentrum Kunstliche Intelligenz, Cyberphys Syst Dept, D-28359 Bremen, Germany
来源
IT-INFORMATION TECHNOLOGY | 2014年 / 56卷 / 06期
关键词
Security; workflows; information-flow control; non-interference;
D O I
10.1515/itit-2014-1055
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Workflow management plays an important role in analyzing and automating business processes. Security requirements in workflow management systems are typicallymapped to (role-based) access control configurations. This paper focuses on information flow control, taking into account implicit information leaks. The presented approach operates on a specification level in which no executable programis available yet. We illustrate the modeling of a workflowmanagement systemas a composition of state-event systems, each representing one of the activities of the workflow. This facilitates distributed deployment and eases verification by splitting up the verification of the overall system into verification of the individual components. Confidentiality requirements are modeled in terms of information flow predicates using the MAKS framework and verified following existing decomposition methodologies, which are adapted for open systems with ongoing user interaction. We discuss the interaction with other security requirements, notably separation of duty.
引用
收藏
页码:294 / 299
页数:6
相关论文
共 50 条