Model Checking of Security-Sensitive Business Processes

Model Checking of Security-Sensitive Business Processes
复制标题

安全敏感业务流程的模型检查

DOI:
--
复制
发表时间:
2009
期刊:
USENIX Conference on File and Storage Technologies
影响因子:
--
通讯作者:
Serena Elisa Ponta
Serena Elisa Ponta
中科院分区:
--
文献类型:
--
作者:
A. Armando;Serena Elisa Ponta

文献摘要

被引文献

相似文献

安全敏感业务流程是必须遵守安全要求(例如授权约束)的业务流程。在以前的工作中,它已被证明,模型检查可以有利地用于安全敏感的业务流程的自动分析。但是,建立一个正式的模型,同时考虑工作流和访问控制策略是一个耗时和容易出错的活动。在本文中,我们提出了一种新的方法来模型检查安全敏感的业务流程,允许单独的规范的工作流和相关的安全策略,同时保留的能力,进行全自动分析的过程。为了说明这种方法的有效性,我们描述了它的应用程序版本的贷款发起过程具有RBAC访问控制策略扩展与委托。
Security-sensitive business processes are business processes that must comply with security requirements (e.g. authorization constraints). In previous works it has been shown that model checking can be profitably used for the automatic analysis of security-sensitive business processes. But building a formal model that simultaneously accounts for both the workflow and the access control policy is a time consuming and error-prone activity. In this paper we present a new approach to model checking security-sensitive business processes that allows for the separate specification of the workflow and of the associated security policy while retaining the ability to carry out a fully automatic analysis of the process. To illustrate the effectiveness of the approach we describe its application to a version of the Loan Origination Process featuring an RBAC access control policy extended with delegation.