CRApr 8, 2014

Possibilistic Information Flow Control for Workflow Management Systems

arXiv:1404.1987v13 citations
Originality Incremental advance
AI Analysis

This addresses security verification for workflow management systems, but it is incremental as it builds upon existing verification techniques.

The paper tackles the problem of formally verifying that workflows satisfy security requirements on both data and processes, by defining a formal model and adapting compositional verification techniques for possibilistic information flow control.

In workflows and business processes, there are often security requirements on both the data, i.e. confidentiality and integrity, and the process, e.g. separation of duty. Graphical notations exist for specifying both workflows and associated security requirements. We present an approach for formally verifying that a workflow satisfies such security requirements. For this purpose, we define the semantics of a workflow as a state-event system and formalise security properties in a trace-based way, i.e. on an abstract level without depending on details of enforcement mechanisms such as Role-Based Access Control (RBAC). This formal model then allows us to build upon well-known verification techniques for information flow control. We describe how a compositional verification methodology for possibilistic information flow can be adapted to verify that a specification of a distributed workflow management system satisfies security requirements on both data and processes.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes