{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,31]],"date-time":"2025-12-31T00:06:06Z","timestamp":1767139566226,"version":"build-2238731810"},"publisher-location":"Singapore","reference-count":19,"publisher":"Springer Singapore","isbn-type":[{"value":"9789811506369","type":"print"},{"value":"9789811506376","type":"electronic"}],"license":[{"start":{"date-parts":[[2019,12,1]],"date-time":"2019-12-01T00:00:00Z","timestamp":1575158400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-981-15-0637-6_26","type":"book-chapter","created":{"date-parts":[[2019,12,2]],"date-time":"2019-12-02T07:09:32Z","timestamp":1575270572000},"page":"313-322","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Process Driven Access Control and Authorization Approach"],"prefix":"10.1007","author":[{"given":"John Paul","family":"Kasse","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lai","family":"Xu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paul","family":"de Vrieze","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuewei","family":"Bai","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,12,1]]},"reference":[{"issue":"3","key":"26_CR1","doi-asserted-by":"publisher","first-page":"231","DOI":"10.1145\/293910.293151","volume":"23","author":"E Bertino","year":"1998","unstructured":"E. Bertino, C. Bettini, E. Ferrari, P. Samarati, An access control model supporting periodicity constraints and temporal reasoning. ACM Trans. Database Syst. 23(3), 231 (1998)","journal-title":"ACM Trans. Database Syst."},{"issue":"1","key":"26_CR2","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1145\/300830.300837","volume":"2","author":"E Bertino","year":"1999","unstructured":"E. Bertino, E. Ferrari, V. Atluri, The specification and enforcement of authorization constraints in workflow management systems. ACM Trans. Inf. Syst. Secur. 2(1), 65\u2013104 (1999)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"26_CR3","unstructured":"G. Karjoth, Aligning security and business objectives for process-aware information systems, in Proceedings 5th ACM Conference Data Applied Security Privacy\u2014CODASPY\u201915 (2015) pp. 243\u2013243"},{"key":"26_CR4","doi-asserted-by":"publisher","first-page":"159","DOI":"10.1007\/978-3-642-01982-1_8","volume":"2008","author":"S Sadiq","year":"2010","unstructured":"S. Sadiq, G. Governatori, Managing regulatory compliance in business processes. Handb. Bus. Process Manag. 2, 159\u2013175 (2010)","journal-title":"Handb. Bus. Process Manag. 2"},{"key":"26_CR5","unstructured":"K. Tan, J. Crampton, C.A. Gunter, The consistency of task-based authorization constraints in workflow systems, in Proceedings 17th IEEE Computer Security Foundations Workshop, (2004) pp. 155\u2013169"},{"key":"26_CR6","doi-asserted-by":"crossref","unstructured":"J.P. Kasse, L. Xu, P.T. de Vrieze, The need for compliance verification in collaborative business processes (2018)","DOI":"10.1007\/978-3-319-99127-6_19"},{"key":"26_CR7","unstructured":"O.M.G. Omg, Business Process Model and Notation (BPMN) Version 2.0, in Business, vol. 50 (2011), p. 170"},{"key":"26_CR8","doi-asserted-by":"crossref","unstructured":"M. Salnitri, F. Dalpiaz, P. Giorgini, Modeling and verifying security policies in business processes, in Lecture Notes in Business Information Processing, vol. 175 (LNBIP, 2014), pp. 200\u2013214","DOI":"10.1007\/978-3-662-43745-2_14"},{"key":"26_CR9","unstructured":"G. Monakova, A.D. Brucker, A. Schaad, Security and safety of assets in business processes, in Proceedings of the 27th Annual ACM Symposium on Applied Computing\u2014SAC\u201912 (2012) p. 1667"},{"key":"26_CR10","unstructured":"J. M\u00fcller, Security mechanisms for workflows in service-oriented architectures (2015)"},{"key":"26_CR11","doi-asserted-by":"crossref","unstructured":"G. Koliadis, Verifying semantic business process models in inter-operation, in IEEE International Conference on Services Computing (2007)","DOI":"10.1109\/SCC.2007.128"},{"key":"26_CR12","doi-asserted-by":"crossref","unstructured":"J.P. Kasse, L. Xu, P. de Vrieze, A comparative assessment of collaborative business process verification approaches, vol. 506 (2017)","DOI":"10.1007\/978-3-319-65151-4_33"},{"key":"26_CR13","unstructured":"D. Basin, E.T.H. Zurich, Optimal workflow-aware authorizations, in Proceedings of the 17th ACM Symposium Access Control Models and Technologies ACM (2011) pp. 93\u2013102"},{"key":"26_CR14","unstructured":"A.M. Awad, A Compliance Management Framework for Business Process Models. Ph.D. thesis (2010)"},{"key":"26_CR15","unstructured":"D. Nikovski, B. Akihiro, Workflow trees for representation and mining of implicitly concurrent business processes, in ICEIS 2008\u2014Proceedings of the 10th International Conference on Enterprise Information Systems (ISAS), vol. 2 (2008), pp. 30\u201336"},{"key":"26_CR16","unstructured":"J. Crampton, G. Gutin, Constraint expressions and workflow satisfiability, in Proceedings of the 18th ACM Symposium Access Control Models and Technologies ACM (2013), pp. 73\u201384"},{"key":"26_CR17","unstructured":"D.R. dos Santos, S.E. Ponta, S. Ranise, Modular synthesis of enforcement mechanisms for the workflow satisfiability problem, in Proceedings of the 21st ACM Symposium Access Control Models and Technologies\u2014SACMAT\u201916 (2016), pp. 89\u201399"},{"issue":"2","key":"26_CR18","doi-asserted-by":"publisher","first-page":"133","DOI":"10.3233\/JCS-2008-16203","volume":"16","author":"MC Mont","year":"2008","unstructured":"M.C. Mont, R. Thyne, Privacy policy enforcement in enterprises with identity management solutions. J. Comput. Secur. 16(2), 133\u2013163 (2008)","journal-title":"J. Comput. Secur."},{"key":"26_CR19","unstructured":"M.C. Mont, R. Thyne, A systemic approach to automate privacy policy enforcement in enterprises, in International Workshop on Privacy Enhancing Technologies (2006), pp. 118\u2013134"}],"updated-by":[{"DOI":"10.1007\/978-981-15-0637-6_45","type":"correction","label":"Correction","source":"publisher","updated":{"date-parts":[[2020,4,3]],"date-time":"2020-04-03T00:00:00Z","timestamp":1585872000000}}],"container-title":["Advances in Intelligent Systems and Computing","Fourth International Congress on Information and Communication Technology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-15-0637-6_26","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,4,3]],"date-time":"2020-04-03T01:07:10Z","timestamp":1585876030000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-981-15-0637-6_26"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,12,1]]},"ISBN":["9789811506369","9789811506376"],"references-count":19,"URL":"https:\/\/doi.org\/10.1007\/978-981-15-0637-6_26","relation":{},"ISSN":["2194-5357","2194-5365"],"issn-type":[{"value":"2194-5357","type":"print"},{"value":"2194-5365","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,12,1]]},"assertion":[{"value":"1 December 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"3 April 2020","order":2,"name":"change_date","label":"Change Date","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"Correction","order":3,"name":"change_type","label":"Change Type","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"Compliance to regulatory requirements is key to successful collaborative business process execution. The review of\u00a0the EU General Data Protection Regulation (GDPR) brought to the fore the need to comply with data privacy.","order":4,"name":"change_details","label":"Change Details","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}