DocumentCode :
968374
Title :
Bridging Security and Fault Management within Distributed Workflow Management Systems
Author :
Montagut, Frederic ; Molva, Refik
Author_Institution :
SAP Res., Zurich
Volume :
1
Issue :
1
fYear :
2008
Firstpage :
33
Lastpage :
48
Abstract :
As opposed to centralized workflow management systems, the distributed execution of workflows can not rely on a trusted centralized point of coordination. As a result, basic security features including compliance of the overall sequence of workflow operations with the pre-defined workflow execution plan or traceability become critical issues that are yet to be addressed. Besides, the detection of security inconsistencies during the execution of a workflow usually implies the complete failure of the workflow although it may be possible in some situations to recover from the latter. In this paper, we present security solutions supporting the secure execution of distributed workflows. These mechanisms capitalize on onion encryption techniques and security policy models to assure the integrity of the distributed execution of workflows, to prevent business partners from being involved in a workflow instance forged by a malicious peer and to provide business partners identity traceability for sensitive workflow instances. Moreover, we specify how these security mechanisms can be combined with a transactional coordination framework to recover from faults that may be caught during their execution. The defined solutions can easily be integrated into distributed workflow management systems as our design is strongly coupled with the runtime specification of decentralized workflows.
Keywords :
distributed processing; security of data; software fault tolerance; workflow management software; centralized workflow management systems; distributed workflow management systems; distributed workflows execution; fault management; malicious peer; onion encryption; predefined workflow execution plan; security features; security inconsistencies; security policy models; transactional coordination framework; trusted centralized coordination; workflow instance; Fault detection; Identity-based encryption; Resumes; Routing; Runtime; Security; Workflow management software; Communication/Networking and Information Technology; Compu; Computer Systems Organization; Database Management; Distributed Systems; Distributed applications; Fault tolerance; General; Information Technology and Systems; Performance of Systems; Reliability; Security; and protection; and serviceability; availability; integrity;
fLanguage :
English
Journal_Title :
Services Computing, IEEE Transactions on
Publisher :
ieee
ISSN :
1939-1374
Type :
jour
DOI :
10.1109/TSC.2008.3
Filename :
4663051
Link To Document :
بازگشت