Skip to main navigation Skip to search Skip to main content

Conformance Checking of RBAC Policies in Process-Aware Information Systems

Publication: Chapter in book/Conference proceedingContribution to conference proceedings

Abstract

A process-aware information system (PAIS) is a software system that supports the definition, execution, and analysis of business processes. The execution of process instances is typically recorded in so called event logs. In this paper, we present an approach to automatically generate LTL (Linear Temporal Logic) statements from process-related RBAC (Role-based Access Control) models. These LTL statements are used to check if process executions that are recorded via event logs conform to the access control policies defined via a corresponding RBAC model. To demonstrate our approach, we implemented a RBAC-to-LTL component, and used the ProM tool to test the resulting LTL statements with event logs created from process simulations in CPN tools.
Original languageEnglish
Title of host publicationBPM 2011 Workshops, Part II, LNBIP 100
Editors Farouk Toumani, Karsten Wolf, Stefanie Rinderle-Ma
Place of PublicationClermont-Ferrand, France
PublisherSpringer Verlag
Pages435 - 446
Publication statusPublished - 1 Dec 2011

Cite this