2011
DOI: 10.1007/978-3-642-22056-2_67
|View full text |Cite
|
Sign up to set email alerts
|

Modeling Support for Delegating Roles, Tasks, and Duties in a Process-Related RBAC Context

Abstract: Abstract. The definition of access control concepts at the modeling level is an important prerequisite for the thorough implementation and enforcement of corresponding policies and constraints in a software system. In this paper, we present an approach to provide modeling support for the delegation of roles, tasks, and duties in the context of processrelated RBAC models. The delegation model elements are integrated into a software engineering and business process context by providing UML2 modeling support for … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
8
0

Year Published

2012
2012
2014
2014

Publication Types

Select...
3
2

Relationship

4
1

Authors

Journals

citations
Cited by 6 publications
(8 citation statements)
references
References 17 publications
0
8
0
Order By: Relevance
“…However, this extension does not have any particular connection to process diagrams. In addition, several approaches exist to integrate various security aspects, such as role-based access control concepts [31,32,33] or data integrity and data confidentiality [25] into UML Activity diagrams. However, in contrast to the approach presented in this paper, all other security visualizations only represent presentation options.…”
Section: Discussionmentioning
confidence: 99%
“…However, this extension does not have any particular connection to process diagrams. In addition, several approaches exist to integrate various security aspects, such as role-based access control concepts [31,32,33] or data integrity and data confidentiality [25] into UML Activity diagrams. However, in contrast to the approach presented in this paper, all other security visualizations only represent presentation options.…”
Section: Discussionmentioning
confidence: 99%
“…Our integrated modeling approach for delegation policies and corresponding processes acts as an enabler to document and communicate more efficiently which delegation aspects need to be considered when executing a certain process. To achieve this, we consolidate and extend our previous publications from Schefer and Strembeck (2011b) and Schefer-Wenzl et al (2012): Our approach is based on a metamodel which formally integrates the core elements of process models and delegation models for roles, tasks, and duties (see Fig. 2).…”
Section: Introductionmentioning
confidence: 94%
“…A SOD constraint defines that two permissions/tasks must not be assigned to (or activated/performed by) the same subject, while a BOD constraint defines that two bound permissions/tasks need to be assigned to the same subject or role. Furthermore, some approaches offer modeling support to visualize the respective concepts, some approaches (also) provide corresponding tool support for enforcing delegation or break-glass policies (see, e.g., [37,38,42]). This variety presents a challenge for researchers working in this field or wishing to quickly grasp the state of research.…”
Section: Development Of the Research Areamentioning
confidence: 99%
“…In [37,40], an approach to model the delegation of roles, tasks, and duties in UML Activity diagrams is introduced. In addition, algorithms are introduced to systematically check for conflicts before delegating tasks, duties, and roles in a business process context at design-and runtime.…”
Section: Comparison Of Delegation Approachesmentioning
confidence: 99%