메뉴 건너뛰기




Volumn 56, Issue 10, 2014, Pages 1289-1308

Model-driven specification and enforcement of RBAC break-glass policies for process-aware information systems

Author keywords

Access control; Business process modeling; Model driven development; UML

Indexed keywords

ACCESS CONTROL; INFORMATION SYSTEMS; SPECIFICATIONS; SYSTEMS ANALYSIS; SYSTEMS ENGINEERING;

EID: 84905089674     PISSN: 09505849     EISSN: None     Source Type: Journal    
DOI: 10.1016/j.infsof.2014.04.010     Document Type: Article
Times cited : (8)

References (73)
  • 2
    • 84905103338 scopus 로고    scopus 로고
    • Oracle Role Manager, 2013. < http://www.oracle.com/us/products/ middleware/identity-management/oracle-role-manager/overview/index.html >.
    • (2013) Oracle Role Manager
  • 3
    • 84905115257 scopus 로고    scopus 로고
    • SAP Virsa Firefighter, 2013. < http://sapsecurity.info/virsa- firefighter/ >.
    • (2013) SAP Virsa Firefighter
  • 8
    • 0002848811 scopus 로고    scopus 로고
    • The specification and enforcement of authorization constraints in workflow management systems
    • E. Bertino, E. Ferrari, and V. Atluri The specification and enforcement of authorization constraints in workflow management systems ACM Trans. Inf. Syst. Secur. (TISSEC) 2 1 1999
    • (1999) ACM Trans. Inf. Syst. Secur. (TISSEC) , vol.2 , Issue.1
    • Bertino, E.1    Ferrari, E.2    Atluri, V.3
  • 9
    • 0034810791 scopus 로고    scopus 로고
    • Separation of duties for access control enforcement in workflow environments
    • R.A. Botha, and J.H. Eloff Separation of duties for access control enforcement in workflow environments IBM Syst. J. 40 3 2001
    • (2001) IBM Syst. J. , vol.40 , Issue.3
    • Botha, R.A.1    Eloff, J.H.2
  • 15
    • 0000865747 scopus 로고    scopus 로고
    • Specification and implementation of exceptions in workflow management systems
    • F. Casati, S. Ceri, S. Paraboschi, and G. Pozzi Specification and implementation of exceptions in workflow management systems ACM Trans. Database Syst. 24 1999 405 451
    • (1999) ACM Trans. Database Syst. , vol.24 , pp. 405-451
    • Casati, F.1    Ceri, S.2    Paraboschi, S.3    Pozzi, G.4
  • 16
    • 0033115129 scopus 로고    scopus 로고
    • A meta modeling approach to workflow management systems supporting exception handling
    • D.K.W. Chiu, Q. Li, and K. Karlapalem A meta modeling approach to workflow management systems supporting exception handling Inf. Syst. 24 1999 159 184
    • (1999) Inf. Syst. , vol.24 , pp. 159-184
    • Chiu, D.K.W.1    Li, Q.2    Karlapalem, K.3
  • 26
    • 84899976809 scopus 로고    scopus 로고
    • Modeling and enforcing secure object flows in process-driven SOAs: An integrated model-driven approach
    • B. Hoisl, S. Sobernig, and M. Strembeck Modeling and enforcing secure object flows in process-driven SOAs: an integrated model-driven approach Software Syst. Model. (SoSyM) 13 2 2014
    • (2014) Software Syst. Model. (SoSyM) , vol.13 , Issue.2
    • Hoisl, B.1    Sobernig, S.2    Strembeck, M.3
  • 29
    • 33745167684 scopus 로고    scopus 로고
    • When and how to develop domain-specific languages
    • M. Mernik, J. Heering, and A.M. Sloane When and how to develop domain-specific languages ACM Comput. Surv. (CSUR) 34 4 2005 316 344
    • (2005) ACM Comput. Surv. (CSUR) , vol.34 , Issue.4 , pp. 316-344
    • Mernik, M.1    Heering, J.2    Sloane, A.M.3
  • 30
    • 77954504239 scopus 로고    scopus 로고
    • From goal-driven security requirements engineering to secure design
    • H. Mouratidis, and J. Jürjens From goal-driven security requirements engineering to secure design Int. J. Intell. Syst. 25 8 2010
    • (2010) Int. J. Intell. Syst. , vol.25 , Issue.8
    • Mouratidis, H.1    Jürjens, J.2
  • 32
    • 0038825675 scopus 로고    scopus 로고
    • Task-role-based access control model
    • S. Oh, and S. Park Task-role-based access control model Inf. Syst. 28 6 2003
    • (2003) Inf. Syst. , vol.28 , Issue.6
    • Oh, S.1    Park, S.2
  • 33
    • 84905108671 scopus 로고    scopus 로고
    • OMG January 2009, Version 1.2, formal/2009-01-03, The Object Management Group
    • OMG. OMG Business Process Modeling Notation, < http://www.omg.org/ spec/BPMN/1.2/ > January 2009, Version 1.2, formal/2009-01-03, The Object Management Group.
    • OMG Business Process Modeling Notation
  • 34
    • 84883792913 scopus 로고    scopus 로고
    • OMG February 2010, Version 2.2, formal/2010-02-01, The Object Management Group
    • OMG. Object Constraint Language Specification, < http://www.omg.org/ technology/documents/formal/ocl.htm > February 2010, Version 2.2, formal/2010-02-01, The Object Management Group.
    • Object Constraint Language Specification
  • 35
    • 77951438093 scopus 로고    scopus 로고
    • OMG May 2010. Version 2.3, formal/2010-05-03, The Object Management Group
    • OMG, Unified Modeling Language (OMG UML): Superstructure, < http://www.omg.org/technology/documents/formal/uml.htm > May 2010. Version 2.3, formal/2010-05-03, The Object Management Group.
    • Unified Modeling Language (OMG UML): Superstructure
  • 39
    • 0032024112 scopus 로고    scopus 로고
    • Adept-flex-supporting dynamic changes of workflows without losing control
    • M. Reichert, and P. Dadam Adept-flex-supporting dynamic changes of workflows without losing control J. Intell. Inf. Syst. 10 2 1998
    • (1998) J. Intell. Inf. Syst. , vol.10 , Issue.2
    • Reichert, M.1    Dadam, P.2
  • 43
    • 61849169018 scopus 로고    scopus 로고
    • Guidelines for conducting and reporting case study research in software engineering
    • P. Runeson, and M. Höst Guidelines for conducting and reporting case study research in software engineering Empirical Software Eng. 14 2 2009
    • (2009) Empirical Software Eng. , vol.14 , Issue.2
    • Runeson, P.1    Höst, M.2
  • 47
    • 84898423580 scopus 로고    scopus 로고
    • Modeling support for delegating roles, tasks, and duties in a process-related RBAC context
    • Lecture Notes in Business Information Processing (LNBIP) Springer Verlag
    • S. Schefer, and M. Strembeck Modeling support for delegating roles, tasks, and duties in a process-related RBAC context International Workshop on Information Systems Security Engineering (WISSE) Lecture Notes in Business Information Processing (LNBIP) 2011 Springer Verlag
    • (2011) International Workshop on Information Systems Security Engineering (WISSE)
    • Schefer, S.1    Strembeck, M.2
  • 54
    • 33344465743 scopus 로고    scopus 로고
    • Model-driven engineering - Guest editorś introduction
    • D.C. Schmidt Model-driven engineering - guest editorś introduction IEEE Comput. 39 2 2006
    • (2006) IEEE Comput. , vol.39 , Issue.2
    • Schmidt, D.C.1
  • 55
    • 0141725660 scopus 로고    scopus 로고
    • The pragmatics of model-driven development
    • B. Selic The pragmatics of model-driven development IEEE Software 20 5 2003
    • (2003) IEEE Software , vol.20 , Issue.5
    • Selic, B.1
  • 58
    • 77249095368 scopus 로고    scopus 로고
    • Scenario-driven role engineering
    • M. Strembeck Scenario-driven role engineering IEEE Secur. Privacy 8 1 2010
    • (2010) IEEE Secur. Privacy , vol.8 , Issue.1
    • Strembeck, M.1
  • 59
    • 78650098860 scopus 로고    scopus 로고
    • Generic algorithms for consistency checking of mutual-exclusion and binding constraints in a business process context
    • Lecture Notes in Computer Science (LNCS) Springer Verlag
    • M. Strembeck, and J. Mendling Generic algorithms for consistency checking of mutual-exclusion and binding constraints in a business process context Proc. of the 18th International Conference on Cooperative Information Systems (CoopIS) Lecture Notes in Computer Science (LNCS) vol. 6426 2010 Springer Verlag
    • (2010) Proc. of the 18th International Conference on Cooperative Information Systems (CoopIS) , vol.6426
    • Strembeck, M.1    Mendling, J.2
  • 60
    • 79952439750 scopus 로고    scopus 로고
    • Modeling process-related RBAC models with extended UML activity models
    • M. Strembeck, and J. Mendling Modeling process-related RBAC models with extended UML activity models Inf. Software Technol. 53 5 2011
    • (2011) Inf. Software Technol. , vol.53 , Issue.5
    • Strembeck, M.1    Mendling, J.2
  • 61
    • 4444246080 scopus 로고    scopus 로고
    • An integrated approach to engineer and enforce context constraints in RBAC environments
    • M. Strembeck, and G. Neumann An integrated approach to engineer and enforce context constraints in RBAC environments ACM Trans. Inf. Syst. Secur. (TISSEC) 7 3 2004
    • (2004) ACM Trans. Inf. Syst. Secur. (TISSEC) , vol.7 , Issue.3
    • Strembeck, M.1    Neumann, G.2
  • 62
    • 70349874815 scopus 로고    scopus 로고
    • An approach for the systematic development of domain-specific languages
    • M. Strembeck, and U. Zdun An approach for the systematic development of domain-specific languages Software: Pract. Exper. (SP&E) 39 15 2009
    • (2009) Software: Pract. Exper. (SP&E) , vol.39 , Issue.15
    • Strembeck, M.1    Zdun, U.2
  • 65
    • 33846798443 scopus 로고    scopus 로고
    • Deadline-based escalation in process-aware information systems
    • W.M.P. van der Aalst, M. Rosemann, and M. Dumas Deadline-based escalation in process-aware information systems Decis. Support Syst. 43 2007 492 511
    • (2007) Decis. Support Syst. , vol.43 , pp. 492-511
    • Van Der Aalst, W.M.P.1    Rosemann, M.2    Dumas, M.3
  • 66
    • 84905100381 scopus 로고    scopus 로고
    • Embedding 'break the glass' into business process models
    • S. von Stackelberg, K. Böhm, M. Bracht, Embedding 'break the glass' into business process models, in: OTM Conferences (1), 2012.
    • (2012) OTM Conferences , Issue.1
    • Von Stackelberg, S.1    Böhm, K.2    Bracht, M.3
  • 67
    • 0348209180 scopus 로고    scopus 로고
    • W-RBAC - A workflow security model incorporating controlled overriding of constraints
    • J. Wainer, P. Barthelmess, and A. Kumar W-RBAC - a workflow security model incorporating controlled overriding of constraints Int. J. Coop. Inf. Syst. (IJCIS) 12 4 2003
    • (2003) Int. J. Coop. Inf. Syst. (IJCIS) , vol.12 , Issue.4
    • Wainer, J.1    Barthelmess, P.2    Kumar, A.3
  • 71
    • 38049132539 scopus 로고    scopus 로고
    • Modeling of task-based authorization constraints in BPMN
    • G. Alonso, P. Dadam, M. Rosemann, Lecture Notes in Computer Science Springer Berlin/ Heidelberg
    • C. Wolter, and A. Schaad Modeling of task-based authorization constraints in BPMN G. Alonso, P. Dadam, M. Rosemann, Business Process Management Lecture Notes in Computer Science vol. 4714 2007 Springer Berlin/ Heidelberg
    • (2007) Business Process Management , vol.4714
    • Wolter, C.1    Schaad, A.2
  • 73
    • 34249655677 scopus 로고    scopus 로고
    • Object-based and class-based composition of transitive mixins
    • U. Zdun, M. Strembeck, and G. Neumann Object-based and class-based composition of transitive mixins Inf. Software Technol. 49 8 2007
    • (2007) Inf. Software Technol. , vol.49 , Issue.8
    • Zdun, U.1    Strembeck, M.2    Neumann, G.3


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.