DocumentCode
1834049
Title
Security Policies in Adaptive Process-Aware Information Systems: Existing Approaches and Challenges
Author
Leitner, Maria
Author_Institution
Univ. of Vienna, Vienna, Austria
fYear
2011
fDate
22-26 Aug. 2011
Firstpage
686
Lastpage
691
Abstract
Enabling security is one of the key challenges in adaptive Process-Aware Information Systems (PAIS). Since automating business processes involves many participants, uses private and public data, and communicates with external services security becomes inevitable. In current systems, security is enforced by an access control model and supplementary constraints imposed on workflow activities. However, existing systems provide individual implementations for security policies (e.g. separation of duties) and leave out other constraints (e.g. inter-process constraints). What is missing is a systematic analysis of security policies in PAIS. Hence, in this paper, we display state of the art and provide a taxonomy of security policies in PAIS. Furthermore, a detailed analysis of research challenges and issues is presented. We will show that there are still shortcomings and identify important requirements for security in PAIS. We will also point out open questions related to specifying, modeling, and changing security policies which will provide a road map for future research.
Keywords
business data processing; information systems; security of data; access control model; adaptive process-aware information system; business process; security policy; Authorization; Availability; Educational institutions; Guidelines; Unified modeling language; Process-Aware Information Systems; Security Policies;
fLanguage
English
Publisher
ieee
Conference_Titel
Availability, Reliability and Security (ARES), 2011 Sixth International Conference on
Conference_Location
Vienna
Print_ISBN
978-1-4577-0979-1
Electronic_ISBN
978-0-7695-4485-4
Type
conf
DOI
10.1109/ARES.2011.107
Filename
6046046
Link To Document