• DocumentCode
    1831199
  • Title

    AW-RBAC: Access Control in Adaptive Workflow Systems

  • Author

    Leitner, Maria ; Rinderle-Ma, Stefanie ; Mangler, Juergen

  • Author_Institution
    Univ. of Vienna, Vienna, Austria
  • fYear
    2011
  • fDate
    22-26 Aug. 2011
  • Firstpage
    27
  • Lastpage
    34
  • Abstract
    Flexibility is one of the key challenges for Workflow Systems nowadays. Typically, a workflow covers the following four aspects which might all be subject to change: control flow, data flow, organizational structures, and application components (services). Existing work in research and practice shows that changes must be applied in a controlled manner in order to avoid security problems. In this context, attempts have been made to manage administrative or operative changes using role-based access control (RBAC) models. However, most approaches focus on either administrative changes such as role updating and administration or operative changes, for example, inserting a new activity into a running workflow instance. The distinct handling of certain changes is cumbersome and hence should be reduced by introducing a RBAC model that pays attention to all kinds of possible workflow changes. Hence, in this paper, we present an extended RBAC model for adaptive workflow systems (AW-RBAC) that includes change operations and a variety of objects that are subject to change within workflow systems. Under such a model supervised administrative and operative changes can be enforced on a set of objects in workflow systems. Doing so, the AW-RBAC model improves security during workflow changes and reduces administration costs. The AW-RBAC model is evaluated by means of practical examples and a proof-of-concept implementation.
  • Keywords
    authorisation; workflow management software; AW-RBAC model; adaptive workflow system; application component aspect; control flow aspect; data flow aspect; organizational structure aspect; role-based access control; Access control; Adaptation models; Context; Monitoring; Permission; Process control; Access Control; Process-Aware Information Systems; RBAC;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2011 Sixth International Conference on
  • Conference_Location
    Vienna
  • Print_ISBN
    978-1-4577-0979-1
  • Electronic_ISBN
    978-0-7695-4485-4
  • Type

    conf

  • DOI
    10.1109/ARES.2011.15
  • Filename
    6045935