Title :
Consistency Checks for Duties in Extended UML2 Activity Models
Author_Institution :
Inst. for Inf. Syst. & New Media, Vienna Univ. of Econ. & Bus. (WU Vienna), Vienna, Austria
Abstract :
Process-aware information systems support the execution of business processes. Organizations require the precise specification of security policies that govern the behavior of subjects in these systems. Thereby, obligation policies specify duties to be fulfilled by certain subjects. In organizational contexts, duties are often associated with a certain task in a business process. In this paper, we further elaborate two UML2 extensions which provide modeling support for roles, tasks, and duties in a business process context. In particular, we introduce the notion of mutual exclusion and binding constraints for duties in process-related RBAC models. Furthermore, we formally define respective consistency checks for design-time and runtime models.
Keywords :
Unified Modeling Language; data flow analysis; security of data; binding constraints; business processes; consistency checks; design-time models; extended UML2 activity models; mutual exclusion; organizational contexts; process-aware information systems; process-related RBAC models; runtime models; security policy specification; Biological system modeling; Context; Contracts; Information systems; Runtime; Unified modeling language; Binding of duty; OCL; RBAC; Security; Separation of Duty; UML;
Conference_Titel :
Availability, Reliability and Security (ARES), 2011 Sixth International Conference on
Conference_Location :
Vienna
Print_ISBN :
978-1-4577-0979-1
Electronic_ISBN :
978-0-7695-4485-4
DOI :
10.1109/ARES.2011.106