Exposeè

Short overview

Process Aware Information Systems (PAIS) allow to support groups of users in organizing or coordination sequences of tasks. These sequences are refereed to as processes, in a business environment they typically are the representation of a business logic. This business logic is typically driven by 2 types of actors: 
 
Tasks involving humans are typically supported by a worklist handler. The purpose of a worklist handler is to distribute the work to one or more human actors that may be entitled to work on a particular task.  
 
As the processes are a manifestation of the business logic, they are very important for a company, and are typically constrained by a set of rules. These rules either stem from internal necessity (e.g. a diverse workforce, internal security rules), or from external sources (e.g. laws). The creation of these rules is driven by the following basic security facts:  
 
On a technical level, processes are executed by a process engine (PE), which together with the worklist (WL) is responsible for an efficient and secure (regarding the above mentioned facts) execution of processes. In order to do so, not only the business logic but also the accompanying security facts, have to be well formalized and available in machine readable and interpretable form. While the creation of processes is supported by a wide range of process editors [REF jBPM Signavio), for security rules the tool support often only support certain security aspects, and is not formalized or standardized. Also the security support is often tightly integrated with the processes and their syntax, allowing for no independent management of security aspects.  

Goals, Contributions

The goal of this work is to create an editor, to support the efficient management of security rules for PAIS, based on the formalization developed by Leitner, Mangler and Rinderle-Ma. The purpose of this editor is to allow for an independent management and audit of process related security concepts. The contributions will include: 
 
Furthermore a backend-system will be provided, that manages the data created by the editors as a restful service. 
Finally this thesis will also provide a well defined testset (including security rules and example processes) as well as a test program to find out which rules apply for certain tasks.  
 
This thesis will not provide a language or library to match process patterns: for this case either LTL (Linear Temporal Logic), or alternatively the ppmex (Process Pattern Matching Expressions) formalism developed by the WST group, will be used. 

Table of Contents

LaTeX Version LaTeX Version
Letzte Änderung: 03.09.2013, 16:07 | 695 Worte