Architectural Alignment of Access Control Requirements Extracted from Business Processes
Abstract
Business processes and information systems evolve constantly and affect each other in non-trivial ways. Aligning security requirements between both is a challenging task. This work presents an automated approach to extract access control requirements from business processes with the purpose of transforming them into a) access permissions for role-based access control and b) architectural data flow constraints to identify violations of access control in enterprise application architectures.
Keywords
Software Engineering; Enterprise Architecture; Zugriffskontrolle; Geschäftsprozesse; Access Control; Business ProcessesDOI
10.5445/KSP/1000148100ISBN
9783731512127Publisher
KIT Scientific PublishingPublisher website
https://www.ksp.kit.edu/index.php?link=shop&sort=allPublication date and place
2023Series
The Karlsruhe Series on Software Design and Quality, 37Classification
Maths for computer scientists