BP-XACML: An authorisation policy language for business processes


Autoria(s): Alissa, Khalid; Reid, Jason; Dawson, Ed; Salim, Farzad
Contribuinte(s)

Foo, Ernest

Stebila, Douglas

Data(s)

22/04/2015

Resumo

XACML has become the defacto standard for enterprise- wide, policy-based access control. It is a structured, extensible language that can express and enforce complex access control policies. There have been several efforts to extend XACML to support specific authorisation models, such as the OASIS RBAC profile to support Role Based Access Control. A number of proposals for authorisation models that support business processes and workflow systems have also appeared in the literature. However, there is no published work describing an extension to allow XACML to be used as a policy language with these models. This paper analyses the specific requirements of a policy language to express and enforce business process authorisation policies. It then introduces BP-XACML, a new profile that extends the RBAC profile for XACML so it can support business process authorisation policies. In particular, BP-XACML supports the notion of tasks, and constraints at the level of a task instance, which are important requirements in enforcing business process authorisation policies.

Formato

application/pdf

Identificador

http://eprints.qut.edu.au/83935/

Publicador

Springer

Relação

http://eprints.qut.edu.au/83935/1/BP-XACML.pdf

http://www.springer.com/services+for+this+book?SGWID=0-1772415-3260-0-9783319199610

DOI:10.1007/978-3-319-19962-7_18

Alissa, Khalid, Reid, Jason, Dawson, Ed, & Salim, Farzad (2015) BP-XACML: An authorisation policy language for business processes. In Foo, Ernest & Stebila, Douglas (Eds.) Information Security and Privacy: 20th Australasian Conference, ACISP 2015, Proceedings [Lecture Notes in Computer Science, Volume 9144], Springer, QUT Gardens Point, Brisbane, Australia, pp. 307-325.

Direitos

Copyright 2015 [please consult the authors]

Fonte

Computer Science; Institute for Future Environments; Science & Engineering Faculty

Palavras-Chave #080000 INFORMATION AND COMPUTING SCIENCES #Authorisation policy language #Authorisation management #XACML #BPM #Workflow #Business Process
Tipo

Conference Paper