Real-life business process specifications include situations where work may be repeated due to exceptions such as the lack of resources or failed approvals. However, most authorization constraint models for business processes describe them as partially ordered sets of tasks. This abstraction simplifies the analysis of constraints greatly but prevents their use in real systems because control flows with loops are not supported. To overcome this limitation, we scope authorization constraints to task instances using the concept of release, which removes associations between users and their previously executed tasks. We define a model applying releases to cardinality and interval constraints, such as Separation of Duty (SoD). The latter is based on the notion of intervals defined by pairs of tasks and imposing conditions on the users executing them. We extend BPMN to visualize our constraints, bridging the gap between IT and business people as well as to auditors. © 2012 Springer-Verlag.
CITATION STYLE
Burri, S. J., & Karjoth, G. (2012). Flexible scoping of authorization constraints on business processes with loops and parallelism. In Lecture Notes in Business Information Processing (Vol. 100 LNBIP, pp. 411–422). Springer Verlag. https://doi.org/10.1007/978-3-642-28115-0_39
Mendeley helps you to discover research relevant for your work.