{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,6]],"date-time":"2026-03-06T15:06:15Z","timestamp":1772809575222,"version":"3.50.1"},"reference-count":37,"publisher":"Springer Science and Business Media LLC","issue":"9","license":[{"start":{"date-parts":[[2015,10,1]],"date-time":"2015-10-01T00:00:00Z","timestamp":1443657600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Computing"],"published-print":{"date-parts":[[2016,9]]},"DOI":"10.1007\/s00607-015-0476-3","type":"journal-article","created":{"date-parts":[[2015,10,1]],"date-time":"2015-10-01T07:38:13Z","timestamp":1443685093000},"page":"847-870","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Automation of service-based security-aware business processes in the Cloud"],"prefix":"10.1007","volume":"98","author":[{"given":"Fernando","family":"Lins","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Julio","family":"Damasceno","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Robson","family":"Medeiros","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Erica","family":"Sousa","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nelson","family":"Rosa","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2015,10,1]]},"reference":[{"key":"476_CR1","unstructured":"Activiti (2013) Activiti 5.15 User Guide. http:\/\/activiti.org\/userguide\/index.html . Last visit at 18 June 2014"},{"key":"476_CR2","doi-asserted-by":"crossref","unstructured":"Altuhhova O, Matulevicius R, Ahmed N (2013) An extension of business process model and notation for security risk management. Technical report. http:\/\/www.techrepublic.com\/resource-library\/whitepapers . Last visit at 08 June 2014","DOI":"10.4018\/ijismd.2013100105"},{"key":"476_CR3","unstructured":"Apache Software Foundation (2009) Apache Rampart\u2014Axis2 Security Model. http:\/\/ws.apache.org\/rampart\/ . Last visit at 3 May 2012"},{"key":"476_CR4","unstructured":"Apache Software Foundation (2008) Apache Orchestration Director Engine (ODE). http:\/\/ode.apache.org\/ . Last visit at 3 May 2013"},{"key":"476_CR5","unstructured":"Appian (2014) Delivering value, security, and speed with BPM in the Cloud. http:\/\/www.appian.com\/bpm-software\/cloud-bpm.jsp . Last visit 14 July 2014"},{"key":"476_CR6","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-540-87742-4","volume-title":"Security for Web services and service-oriented architectures","author":"E Bertino","year":"2010","unstructured":"Bertino E et al (2010) Security for Web services and service-oriented architectures. Springer, Berlin"},{"issue":"4","key":"476_CR7","doi-asserted-by":"crossref","first-page":"212","DOI":"10.1109\/TDSC.2013.6","volume":"10","author":"J Bohli","year":"2013","unstructured":"Bohli J et al (2013) Security and privacy-enhancing multicloud architectures. IEEE Trans Dependable Secur Comput 10(4):212\u2013224","journal-title":"IEEE Trans Dependable Secur Comput"},{"issue":"6","key":"476_CR8","first-page":"239","volume":"55","author":"AD Brucker","year":"2013","unstructured":"Brucker AD (2013) Integrating security aspects into business process models. Inf Technol 55(6):239\u2013246","journal-title":"Inf Technol"},{"issue":"4","key":"476_CR9","doi-asserted-by":"crossref","first-page":"386","DOI":"10.1504\/IJWGS.2012.051527","volume":"8","author":"A Charfi","year":"2012","unstructured":"Charfi A, Schmeling B, Mezini M (2012) An aspect-oriented framework for specification and enforcement of non-functional concerns in WS-BPEL. Int J Web Grid Serv 8(4):386\u2013424","journal-title":"Int J Web Grid Serv"},{"key":"476_CR10","unstructured":"Eclipse Foundation (2008) The BPMN Modeler. http:\/\/www.eclipse.org\/bpmn . Last visit 5 Feb 2012"},{"key":"476_CR11","unstructured":"Eucalyptus Systems (2009) Eucalyptus open-source Cloud computing infrastructure\u2014an overview. http:\/\/www.eucalyptus.com\/whitepapers"},{"key":"476_CR12","doi-asserted-by":"crossref","unstructured":"Fan G et al (2010) Aspect oriented approach to building secure service composition. In: Proceedings of the 17th Asia Pacific software engineering conference (APSEC), pp 176\u2013185","DOI":"10.1109\/APSEC.2010.29"},{"key":"476_CR13","unstructured":"Giner P, Torres V, Pelechano V (2007) Bridging the Gap between BPMN and WS-BPEL: M2M transformations in practice. Technical report. http:\/\/citeseerx.ist.psu.edu\/viewdoc\/summary?doi=10.1.1.83.6295 . Last visit 20 Oct 2013"},{"issue":"9","key":"476_CR14","first-page":"1","volume":"2","author":"J Huang","year":"2013","unstructured":"Huang J, Nicol DM (2013) Trust mechanisms for cloud computing. J Cloud Comput 2(9):1\u201314","journal-title":"J Cloud Comput"},{"key":"476_CR15","unstructured":"IBM (2012) IBM Business Process Manager on Cloud. http:\/\/www-03.ibm.com\/software\/products\/en\/business-process-manager-cloud . Last visit 14 July 2014"},{"key":"476_CR16","unstructured":"ITU-T (1991) Security architecture for open system interconnection for CCITT applications. Recommendation X.800. Geneva, Switzerland"},{"key":"476_CR17","unstructured":"ITU-T (2008) Recommendation Z.150 (02\/03): User Requirements Notation (URN)\u2014Language definition. Geneva, Switzerland"},{"key":"476_CR18","unstructured":"Jboss Community (2014) JBoss jBPM User Guide v. 6.1. http:\/\/docs.jboss.org\/jbpm\/v6.1.0.CR1\/userguide\/ . Last visit at 10 July 2014"},{"key":"476_CR19","doi-asserted-by":"crossref","unstructured":"Leitner M et al (2013) An experimental study on the design and modeling of security concepts in business processes. In: Proceedings of the 6th IFIP WG 8.1 working conference on the practice of enterprise modeling. LNBIP, vol. 165. Springer, Berlin, pp 236\u2013250","DOI":"10.1007\/978-3-642-41641-5_17"},{"key":"476_CR20","doi-asserted-by":"crossref","unstructured":"Menzel M et al (2010) The Service Security Lab: a model-driven platform to compose and explore service security in the Cloud. In: Proceedings of the IEEE international world congress of services, pp 115\u2013122","DOI":"10.1109\/SERVICES.2010.90"},{"key":"476_CR21","doi-asserted-by":"crossref","unstructured":"Menzel M, Warschofsky R, Meinel C (2010) A pattern-driven generation of security policies for service-oriented architectures. In: Proceddings of the IEEE international conference on Web services (ICWS 2010), pp 243\u2013250","DOI":"10.1109\/ICWS.2010.25"},{"key":"476_CR22","doi-asserted-by":"crossref","unstructured":"Mell P, Grance T (2011) The NIST definition of Cloud computing. Recommendations of the National Institute of Standards and Technology, Special Publication 800-145","DOI":"10.6028\/NIST.SP.800-145"},{"key":"476_CR23","unstructured":"OASIS (2007) Web Services Security: SOAP Message Security 1.1. http:\/\/www.oasis-open.org\/committees\/download.php\/16790\/wss-v1.1-spec-os-SOAPMessageSecurity.pdf . Last visit 27 March 2015"},{"key":"476_CR24","unstructured":"OMG (2011) Business process model and notation v 2.0. http:\/\/www.omg.org\/spec\/BPMN\/2.0\/PDF\/ . Last visit 24 Feb 2012"},{"issue":"1","key":"476_CR25","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/1555392.1555395","volume":"19","author":"C Ouyang","year":"2009","unstructured":"Ouyang C et al (2009) From business process models to process-oriented software systems. ACM Trans Softw Eng Methodol 19(1):1\u201337","journal-title":"ACM Trans Softw Eng Methodol"},{"key":"476_CR26","doi-asserted-by":"crossref","first-page":"77","DOI":"10.1007\/978-3-642-29231-6_7","volume":"106","author":"E Paja","year":"2012","unstructured":"Paja E et al (2012) Security requirements engineering for secure business processes. Lect Notes Bus Inf Process 106:77\u201389","journal-title":"Lect Notes Bus Inf Process"},{"key":"476_CR27","doi-asserted-by":"crossref","first-page":"389","DOI":"10.1007\/s00778-007-0044-3","volume":"16","author":"M Papazoglou","year":"2007","unstructured":"Papazoglou M, Heuvel W (2007) Service oriented architectures: approaches, technologies and research issues. VLDB J 16:389\u2013415","journal-title":"VLDB J"},{"key":"476_CR28","doi-asserted-by":"crossref","first-page":"446","DOI":"10.1016\/j.dss.2011.01.018","volume":"51","author":"A Rodriguez","year":"2011","unstructured":"Rodriguez A, Fernndez-Medina E, Trujillo J, Piattini M (2011) Secure business process model specification through a UML 2.0 activity diagram profile. Decis Support Syst 51:446\u2013465","journal-title":"Decis Support Syst"},{"issue":"1","key":"476_CR29","doi-asserted-by":"crossref","first-page":"59","DOI":"10.1590\/S0104-65002004000200006","volume":"10","author":"NS Rosa","year":"2004","unstructured":"Rosa NS, Justo GRR, Cunha PRF (2004) An approach for reasoning and refining non-functional requirements. J Braz Comput Soc 10(1):59\u201377","journal-title":"J Braz Comput Soc"},{"key":"476_CR30","unstructured":"Rosa NS et al (2014) Enforcement of security requirements for a business model. US Patent 8,732,094, 2014"},{"key":"476_CR31","doi-asserted-by":"crossref","unstructured":"Schmeling B et al (2011) Composing non-functional concerns in composite Web services. In: 2011 IEEE international conference on Web services, pp 331\u2013338","DOI":"10.1109\/ICWS.2011.111"},{"key":"476_CR32","unstructured":"Stollberg M et al (2004) WSMO use case modeling and testing. http:\/\/www.wsmo.org\/2004\/d3\/d3.2\/20041004 . Last visit 29 May 2013"},{"key":"476_CR33","doi-asserted-by":"crossref","unstructured":"Stango A, Prasad NR, Kyriazanos DM (2009) A threat analysis methodology for security evaluation and enhancement planning. In: Third international conference on emerging security information, systems and technologies, pp 262\u2013267","DOI":"10.1109\/SECURWARE.2009.47"},{"key":"476_CR34","doi-asserted-by":"crossref","first-page":"76","DOI":"10.1007\/978-3-642-31072-0_6","volume":"113","author":"SH Turki","year":"2012","unstructured":"Turki SH et al (2012) Modeling security requirements in service based business processes. Lect Notes Bus Inf Process 113:76\u201390","journal-title":"Lect Notes Bus Inf Process"},{"key":"476_CR35","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1007\/978-3-642-33018-6_2","volume":"189","author":"AJ Varela-Vaca","year":"2013","unstructured":"Varela-Vaca AJ et al (2013) A security pattern-driven approach toward the automation of risk treatment in business processes. Adv Intell Syst Comput 189:13\u201323","journal-title":"Adv Intell Syst Comput"},{"key":"476_CR36","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1016\/j.sysarc.2008.10.002","volume":"55","author":"C Wolter","year":"2009","unstructured":"Wolter C et al (2009) Model-driven business process security requirement specification. J Syst Archit 55:211\u2013223","journal-title":"J Syst Archit"},{"key":"476_CR37","doi-asserted-by":"crossref","unstructured":"Yahia I, Turki SH, Charfi A, Kallel S, Bouaziz R (2013) International conference on service oriented computing workshops (ICSOC Workshops), pp 344\u2013355","DOI":"10.1007\/978-3-642-37804-1_35"}],"container-title":["Computing"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00607-015-0476-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00607-015-0476-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00607-015-0476-3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,31]],"date-time":"2019-08-31T04:37:54Z","timestamp":1567226274000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00607-015-0476-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,10,1]]},"references-count":37,"journal-issue":{"issue":"9","published-print":{"date-parts":[[2016,9]]}},"alternative-id":["476"],"URL":"https:\/\/doi.org\/10.1007\/s00607-015-0476-3","relation":{},"ISSN":["0010-485X","1436-5057"],"issn-type":[{"value":"0010-485X","type":"print"},{"value":"1436-5057","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,10,1]]}}}