Arid
DOI10.1007/978-3-319-19962-7_18
BP-XACML an Authorisation Policy Language for Business Processes
Alissa, Khalid1,2; Reid, Jason1; Dawson, Ed1; Salim, Farzad1
通讯作者Alissa, Khalid
会议名称20th Australasian Conference on Information Security and Privacy (ACISP)
会议日期JUN 29-JUL 01, 2015
会议地点Brisbane, AUSTRALIA
英文摘要

XACML has become the defacto standard for enterprisewide, policy-based access control. It is a structured, extensible language that can express and enforce complex access control policies. There have been several efforts to extend XACML to support specific authorisation models, such as the OASIS RBAC profile to support Role Based Access Control. A number of proposals for authorisation models that support business processes and workflow systems have also appeared in the literature. However, there is no published work describing an extension to allow XACML to be used as a policy language with these models. This paper analyses the specific requirements of a policy language to express and enforce business process authorisation policies. It then introduces BP-XACML, a new profile that extends the RBAC profile for XACML so it can support business process authorisation policies. In particular, BP-XACML supports the notion of tasks, and constraints at the level of a task instance, which are important requirements in enforcing business process authorisation policies.


英文关键词XACML BPM Workflow Authorisation management Authorisation policy language
来源出版物INFORMATION SECURITY AND PRIVACY (ACISP 2015)
ISSN0302-9743
EISSN1611-3349
出版年2015
卷号9144
页码307-325
ISBN978-3-319-19961-0
EISBN978-3-319-19962-7
出版者SPRINGER-VERLAG BERLIN
类型Proceedings Paper
语种英语
国家Australia;Saudi Arabia
收录类别CPCI-S
WOS记录号WOS:000364103800018
WOS类目Computer Science, Information Systems ; Computer Science, Theory & Methods
WOS研究方向Computer Science
资源类型会议论文
条目标识符http://119.78.100.177/qdio/handle/2XILL650/303832
作者单位1.Queensland Univ Technol, Inst Future Environm, Brisbane, Qld 4001, Australia;
2.KACST, Riyadh, Saudi Arabia
推荐引用方式
GB/T 7714
Alissa, Khalid,Reid, Jason,Dawson, Ed,et al. BP-XACML an Authorisation Policy Language for Business Processes[C]:SPRINGER-VERLAG BERLIN,2015:307-325.
条目包含的文件
条目无相关文件。
个性服务
推荐该条目
保存到收藏夹
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Alissa, Khalid]的文章
[Reid, Jason]的文章
[Dawson, Ed]的文章
百度学术
百度学术中相似的文章
[Alissa, Khalid]的文章
[Reid, Jason]的文章
[Dawson, Ed]的文章
必应学术
必应学术中相似的文章
[Alissa, Khalid]的文章
[Reid, Jason]的文章
[Dawson, Ed]的文章
相关权益政策
暂无数据
收藏/分享

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。