Knowledge Resource Center for Ecological Environment in Arid Area
DOI | 10.1007/978-3-319-19962-7_18 |
BP-XACML an Authorisation Policy Language for Business Processes | |
Alissa, Khalid1,2; Reid, Jason1; Dawson, Ed1; Salim, Farzad1 | |
通讯作者 | Alissa, Khalid |
会议名称 | 20th Australasian Conference on Information Security and Privacy (ACISP) |
会议日期 | JUN 29-JUL 01, 2015 |
会议地点 | Brisbane, AUSTRALIA |
英文摘要 | XACML has become the defacto standard for enterprisewide, policy-based access control. It is a structured, extensible language that can express and enforce complex access control policies. There have been several efforts to extend XACML to support specific authorisation models, such as the OASIS RBAC profile to support Role Based Access Control. A number of proposals for authorisation models that support business processes and workflow systems have also appeared in the literature. However, there is no published work describing an extension to allow XACML to be used as a policy language with these models. This paper analyses the specific requirements of a policy language to express and enforce business process authorisation policies. It then introduces BP-XACML, a new profile that extends the RBAC profile for XACML so it can support business process authorisation policies. In particular, BP-XACML supports the notion of tasks, and constraints at the level of a task instance, which are important requirements in enforcing business process authorisation policies. |
英文关键词 | XACML BPM Workflow Authorisation management Authorisation policy language |
来源出版物 | INFORMATION SECURITY AND PRIVACY (ACISP 2015) |
ISSN | 0302-9743 |
EISSN | 1611-3349 |
出版年 | 2015 |
卷号 | 9144 |
页码 | 307-325 |
ISBN | 978-3-319-19961-0 |
EISBN | 978-3-319-19962-7 |
出版者 | SPRINGER-VERLAG BERLIN |
类型 | Proceedings Paper |
语种 | 英语 |
国家 | Australia;Saudi Arabia |
收录类别 | CPCI-S |
WOS记录号 | WOS:000364103800018 |
WOS类目 | Computer Science, Information Systems ; Computer Science, Theory & Methods |
WOS研究方向 | Computer Science |
资源类型 | 会议论文 |
条目标识符 | http://119.78.100.177/qdio/handle/2XILL650/303630 |
作者单位 | 1.Queensland Univ Technol, Inst Future Environm, Brisbane, Qld 4001, Australia; 2.KACST, Riyadh, Saudi Arabia |
推荐引用方式 GB/T 7714 | Alissa, Khalid,Reid, Jason,Dawson, Ed,et al. BP-XACML an Authorisation Policy Language for Business Processes[C]:SPRINGER-VERLAG BERLIN,2015:307-325. |
条目包含的文件 | 条目无相关文件。 |
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。