DocumentCode :
2358643
Title :
Security Policy Enforcement in BPEL-Defined Collaborative Business Processes
Author :
Fischer, Klaus-Peter ; Bleimann, Udo ; Fuhrmann, Woldemar ; Furnell, Steven M.
Author_Institution :
Digamma Commun. Consulting GmbH, Darmstadt
fYear :
2007
fDate :
17-20 April 2007
Firstpage :
685
Lastpage :
694
Abstract :
This paper presents an approach to security policy enforcement with collaborative business processes defined using BPEL and deployed across enterprise domain boundaries for execution. The assessment of compliance with security policies at the location where a BPEL script is to be executed is facilitated by re-formulating the security policies with respect to the potential of violation inherent in BPEL The results of an analysis of the security-relevant semantics of BPEL-defined business processes conducted for this purpose indicate the paramount role of information flow analysis in business processes. Based on these results, the paper proposes an XML-based schema for specifying security policies for cross-organisational business processes that allows for automatic checking of BPEL scripts for compliance to these security policies. The paper also introduces a prototype implementation of an automatic compliance check that approves the feasibility of the method for practical application in security policy enforcement.
Keywords :
XML; business data processing; security of data; BPEL-defined collaborative business processes; XML-based schema; automatic compliance check; cross-organisational business processes; enterprise domain boundaries; security policy enforcement; security-relevant semantics; Business communication; Collaboration; Control systems; Informatics; Information analysis; Information security; Manufacturing processes; Process control; Prototypes; Web services; Business Process Execution Language (BPEL); Collaborative Business Processes; Information Flow Analysis; Security Policy Enforcement; Semantic Analysis; Service Oriented Computing (SOC); Web Services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Data Engineering Workshop, 2007 IEEE 23rd International Conference on
Conference_Location :
Istanbul
Print_ISBN :
978-1-4244-0832-0
Electronic_ISBN :
978-1-4244-0832-0
Type :
conf
DOI :
10.1109/ICDEW.2007.4401056
Filename :
4401056
Link To Document :
بازگشت