A logical framework for reasoning about delegation policies in workflow management systems - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Article Dans Une Revue International Journal of Information and Computer Security Année : 2011

A logical framework for reasoning about delegation policies in workflow management systems

Erik H.A. Proper
  • Fonction : Auteur
  • PersonId : 983589
Ehtesham Zahoor
  • Fonction : Auteur
  • PersonId : 855182
François Charoy
Claude Godart
  • Fonction : Auteur
  • PersonId : 830462
  • IdRef : 031091733

Résumé

Task delegation presents one of the business process security leitmotifs. It defines a mechanism that bridges the gap between workflow and access control systems. Delegation completion and authorisation enforcement are specified under specific constraints so-called events. In this article, we aim to reason about delegation events to model task delegation and to specify delegation policies using a logical framework. To that end, we propose an event-based task delegation model to control the delegation execution. We then identify relevant events responsible for the dynamic enforcement of delegation policies. Further, we define a task-oriented access control model to specify delegation constraints into authorisation policies. Finally, we propose a technique to automate the delegation policies integration. Using event calculus, we develop a reasoning tool to control the delegation execution and to increase the compliance of all delegation changes in the existing policy of the workflow.
Fichier principal
Vignette du fichier
IJICS040405_GAALOUL.pdf (691.31 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00677854 , version 1 (13-09-2012)

Identifiants

Citer

Khaled Gaaloul, Erik H.A. Proper, Ehtesham Zahoor, François Charoy, Claude Godart. A logical framework for reasoning about delegation policies in workflow management systems. International Journal of Information and Computer Security, 2011, 4 (4), pp.365-388. ⟨10.1504/IJICS.2011.044825⟩. ⟨hal-00677854⟩
303 Consultations
319 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More