Title
Modeling Access Control Transactions in Enterprise Architecture
Abstract
Enterprise architecture (EA) aims to provide management with appropriate indicators and controls to steer and model service-oriented enterprises. However, the management of EA models change is a challenging task due to complex dependencies when dealing with security constraints such as access control. In this paper, we motivate the use of an access control model in EA. More specifically, we present the role-based access control (RBAC) standard as a mean to model access control transactions in EA. To that end, we present (i) how the concepts of RBAC can be modeled into the Archi Mate enterprise architecture modeling language, and (ii) how RBAC's enforcementis supported with the DEMO enterprise modeling methodology via the business transaction concept. These attempts will help us to identify the conceptual link between RBAC, Archi Mate, and DEMO meta models in order to create a consistent lightweight model for access control in EA. Finally, we illustrate the application of the proposed approach through the handling of an e-Government scenario.
Year
DOI
Venue
2014
10.1109/CBI.2014.26
CBI), 2014 IEEE 16th Conference  
Keywords
DocType
Volume
authorisation,enterprise resource planning,service-oriented architecture,ArchiMate enterprise architecture modeling language,ArchiMate models,DEMO enterprise modeling methodology,DEMO meta models,EA model management,RBAC enforcement,RBAC standard,access control transaction modeling,business transaction concept,enterprise architecture,role-based access control standard,security constraints,service-oriented enterprise model
Conference
1
ISSN
Citations 
PageRank 
2378-1963
4
0.44
References 
Authors
12
3
Name
Order
Citations
PageRank
Khaled Gaaloul111412.71
Sérgio Guerreiro2539.93
Erik Proper3968146.72