Conflict analysis as a means of enforcing static separation of duty requirements in workflow environments

نویسندگان

  • Stephen Perelson
  • Reinhardt A. Botha
چکیده

The increasing reliance on information technology to support business processes has emphasised the need for information security mechanisms. This, however, has resulted in an ever-increasing workload in terms of security administration. Policy-based approaches have been proposed, promising to lighten the workload of security administrators. Separation of duty is one of the principles cited as a requirement when setting up these policy-based mechanisms. Different types of separation of duty policies exist. They can be categorised into policies that can be enforced at administration time, viz. static separation of duty requirements and policies that can be enforced only at execution time, viz. dynamic separation of duty requirements. This paper deals with specifying static separation of duty requirements in role-based workflow environments. It proposes a mathematical model based on the concept of “conflicting entities” to express static separation of duty requirements. It provides a detailed explanation of the integrity checking that must take place at administration time to ensure that specified separation of duty requirements are honoured.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Separation of duties for access control enforcement in workflow environments

Separation of duty, as a security principle, has as its primary objective the prevention of fraud and errors. This objective is achieved by disseminating the tasks and associated privileges for a specific business process among multiple users. This principle is demonstrated in the traditional example of separation of duty found in the requirement of two signatures on a check. Previous work on s...

متن کامل

Access control and separation of duty in agent-based workflow environments

Agent Technology provides a new methodology in implementing workflow environments. This paper is concerned with how this shift in paradigm affects traditional security concepts like access control and separation of duty principles. The discussion focuses on the implementation of task allocation in an agent-based workflow environment (AWE) that is currently being developed. Task allocation is fu...

متن کامل

An XML based approach to enforcing history-based separation of duty policies in heterogeneous workflow environments

In the computing world a new technology occasionally comes along, promising to make dramatic changes to the way computing tasks are performed. The Extensible Markup Language (XML) has been heralded as one such technology. XML promises to provide a universal metadata mechanism for defining, understanding and interchanging information between possibly heterogeneous systems. This paper exploits th...

متن کامل

Compatibility of Safety Properties and Possibilistic Information Flow Security in MAKS

Motivated by typical security requirements of workflow management systems, we consider the integrated verification of both safety properties (e.g. separation of duty) and information flow security predicates of the MAKS framework (e.g. modeling confidentiality requirements). Due to the refinement paradox, enforcement of safety properties might violate possibilistic information flow properties o...

متن کامل

ارزیابی خطر تخلیه بار الکترواستاتیک و راهکارهای کاهش آن

The investigation and identification of principles and basics for electrostatic discharge is one of the most important possibly hazards in the field of high- energetic materials and other industries, in order to prevent the risk of explosions, as well as to consider effective solutions to control and reduce these risks. In this paper, the principles and mechanisms of electrostatic discharge, it...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • South African Computer Journal

دوره 26  شماره 

صفحات  -

تاریخ انتشار 2000