Title :
An approach to extract RBAC models from BPEL4WS processes
Author :
Mendling, Jan ; Strembeck, Mark ; Stermsek, Gerald ; Neumann, Gustaf
Author_Institution :
Dept. of Inf. Syst., Vienna Univ. of Econ. & BA, Austria
Abstract :
The Business Process Execution Language for Web services (BPEL) has become the defacto standard for Web service composition. Yet, it does not address security aspects. This paper is concerned with access control for BPEL based processes. We present an approach to integrate role-based access control (RBAC) and BPEL on the meta-model level. Moreover, we show that such integration can be used to automate steps of the role engineering process. In particular, we extract RBAC models from BPEL processes and present an XSLT converter that transforms BPEL code to the XML import format of the xoRBAC software component.
Keywords :
Internet; XML; authorisation; business data processing; workflow management software; BPEL4WS process; Business Process Execution Language; Web services; XML; role-based access control; xoRBAC software component; Access control; Data mining; Information security; Information systems; Permission; Search engines; Simple object access protocol; Web and internet services; Web services; XML;
Conference_Titel :
Enabling Technologies: Infrastructure for Collaborative Enterprises, 2004. WET ICE 2004. 13th IEEE International Workshops on
Print_ISBN :
0-7695-2183-5
DOI :
10.1109/ENABL.2004.9