{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,6]],"date-time":"2026-03-06T08:08:37Z","timestamp":1772784517424,"version":"3.50.1"},"reference-count":37,"publisher":"Emerald","issue":"5","license":[{"start":{"date-parts":[[2006,10,1]],"date-time":"2006-10-01T00:00:00Z","timestamp":1159660800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2006,10,1]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-heading\">Purpose<\/jats:title><jats:p>This contribution aims to present the core components of a framework and illustrate the main concepts of a methodology for the systematic design and realization of security\u2010critical inter\u2010organizational workflows with a portion of a workflow\u2010scenario drawn from e\u2010government. It is additionally shown how the framework can be adapted to incorporate advanced security patterns like the Qualified Signature, which extends the concept of digital signature by requiring a natural person to sign.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title><jats:p>The framework is based on a methodology that focuses on the correct implementation of security\u2010requirements and consists of a suite of tools that facilitates the cost\u2010efficient realization and management of decentralized, security\u2010critical workflows.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Findings<\/jats:title><jats:p>The framework has been prototypically validated through case studies from the healthcare and e\u2010government sector. Positive results in pilot applications with industrial partners encourage further steps: the set of supported security requirements is continuously extended (e.g. rights delegation, four eyes principle), a testing environment for industrial settings is being implemented, and the requirements for the efficient management of inter\u2010organizational workflows are being analysed systematically.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Practical implications<\/jats:title><jats:p>The framework caters to the needs of an industrial audience, in need of a cost\u2010efficient support for the systematic and correct realization of secure, inter\u2010organizational workflows.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title><jats:p>The contribution provides a description of the Sectet framework. It is shown how it can be adapted to incorporate advanced security patterns like the Qualified Signature, which implement a legal requirement specific to e\u2010government.<\/jats:p><\/jats:sec>","DOI":"10.1108\/10662240610710978","type":"journal-article","created":{"date-parts":[[2007,1,15]],"date-time":"2007-01-15T13:49:45Z","timestamp":1168868985000},"page":"491-506","source":"Crossref","is-referenced-by-count":34,"title":["Sectet: an extensible framework for the realization of secure inter\u2010organizational workflows"],"prefix":"10.1108","volume":"16","author":[{"given":"Michael","family":"Hafner","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ruth","family":"Breu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Berthold","family":"Agreiter","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrea","family":"Nowak","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"key":"key2022032220214938100_b1","doi-asserted-by":"crossref","unstructured":"Aalst, W.M.P.V.D. (2000), \u201cLoosely coupled interorganizational workflows: modeling and analyzing workflows crossing organizational boundaries\u201d, Information and Management, Vol. 37, pp. 67\u201075.","DOI":"10.1016\/S0378-7206(99)00038-5"},{"key":"key2022032220214938100_b2","unstructured":"Alam, M.M., Breu, R. and Breu, M. (2004), \u201cModel driven security for web services (MDS4WS)\u201d, paper presented at the 8th International Multitopic Conference (INMIC) 2004, Lahore."},{"key":"key2022032220214938100_b3","doi-asserted-by":"crossref","unstructured":"Anderson, A.H. (2004), \u201cAn introduction to the web services policy language (WSPL)\u201d, paper presented at 5th IEEE International Workshop on Policies for Distributed Systems and Networks, IEEE Inc., Yorktown Heights, New York.","DOI":"10.1109\/POLICY.2004.1309166"},{"key":"key2022032220214938100_b4","unstructured":"Andrews, T., Curbera, F., Dholakia, H. and Goland, Y. (2003), BPELWS \u2013 Business Process Execution Language for Web Services \u2013 Version 1.1."},{"key":"key2022032220214938100_b5","unstructured":"Arkin, A. (2002), Business Process Modeling Language (BPML), available at: BPMI.org."},{"key":"key2022032220214938100_b6","unstructured":"Austria, R.O. (1999), Austrian Signature Act. Art. 1 of the Act, Austrian Federal Law Gazette, part I, Nr. 190\/1999."},{"key":"key2022032220214938100_b7","unstructured":"Bajaj, S., Box, D. and Chappell, D. (2006), Web Services Policy Framework (WSPolicy), version 1.2."},{"key":"key2022032220214938100_b8","unstructured":"Bartel, M., Boyer, J. and Fox, B. (2002), in Eastlake, D., Reagle, J. and Solo, D. (Eds), XML\u2010Signature Syntax and Processing, W3C Recommendation 12 February 2002, W3C."},{"key":"key2022032220214938100_b9","doi-asserted-by":"crossref","unstructured":"Basin, D., Doser, J. and Lodderstedt, T. (2003), \u201cModel driven security for process\u2010oriented systems\u201d, SACMAT \u201903: Proceedings of the 8th ACM symposium on Access Control Models and Technologies, Como, Italy.","DOI":"10.1145\/775412.775425"},{"key":"key2022032220214938100_b10","doi-asserted-by":"crossref","unstructured":"Bertino, E., Castano, S. and Ferrari, E. (2001), \u201cSecuring XML documents with Author X\u201d, IEEE Internet Computing, Vol. 3, pp. 21\u201031.","DOI":"10.1109\/4236.935172"},{"key":"key2022032220214938100_b11","unstructured":"Bhamidipati, V. and Sandhu, R. (2004), \u201cPush architectures for user role assignment\u201d, Proceedings of the 23nd National Information Systems Security Conference, Tampa, FL, April 13\u201016, 2004."},{"key":"key2022032220214938100_b12","doi-asserted-by":"crossref","unstructured":"Brogi, A., Canal, C., Pimentel, E. and Vallecillo, A. (2004), \u201cFormalizing web service choreographies\u201d, Electronic Notes in Theoretical Computer Sciences, Vol. 105, pp. 73\u201094.","DOI":"10.1016\/j.entcs.2004.05.007"},{"key":"key2022032220214938100_b13","doi-asserted-by":"crossref","unstructured":"Casati, F. and Shan, M.\u2010C. (2002), \u201cEvent\u2010based interaction management for composite e\u2010services in eFlow\u201d, Information Systems Frontiers, Vol. 4, pp. 19\u201031.","DOI":"10.1023\/A:1015374204227"},{"key":"key2022032220214938100_b14","doi-asserted-by":"crossref","unstructured":"Chadwick, D.W., Otenko, A. and Ball, E. (2003), \u201cRole\u2010based access control with X.509 attribute certificates\u201d, IEEE Internet Computing, Vol. 7, pp. 62\u20109.","DOI":"10.1109\/MIC.2003.1189190"},{"key":"key2022032220214938100_b15","unstructured":"Clark, J., Casanave, C., Kanaskie, K., Harvey, B., Clark, J., Smith, N., Yunker, J. and Riemer, K. (2001), ebXML Business Process Specification Schema Version 1.01, UN\/CEFACT and OASIS."},{"key":"key2022032220214938100_b16","doi-asserted-by":"crossref","unstructured":"Dijkman, R.M. and Dumas, M. (2004), \u201cService\u2010oriented design: a multi\u2010viewpoint approach\u201d, International Journal of Cooperative Information Systems, Vol. 13, pp. 337\u201068.","DOI":"10.1142\/S0218843004001012"},{"key":"key2022032220214938100_b17","unstructured":"EU (2004), TrustCom, European Funded Integrated Project, 6th Framework Programme, available at: www.eu\u2010trustcom.com."},{"key":"key2022032220214938100_b18","unstructured":"Grefen, P.W.P.J., Aberer, K., Ludwig, H. and Hoffner, Y. (2001), \u201cCrossFlow: cross\u2010organizational workflow management for service outsourcing in dynamic virtual enterprises\u201d, IEEE Data Engineering Bulletin, Vol. 24, pp. 52\u20107."},{"key":"key2022032220214938100_b19","doi-asserted-by":"crossref","unstructured":"Gudes, E., Olivier, M. and Riet, R.V.D. (1999), \u201cModelling, specifying and implementing workflow security in cyberspace\u201d, Journal of Computer Security, Vol. 7 No. 4, pp. 287\u2010315.","DOI":"10.3233\/JCS-1999-7403"},{"key":"key2022032220214938100_b20","unstructured":"Gudgin, M., Hadley, M., Mendelsohn, N., Moreau, J.\u2010J. and Nielsen, H.F. (2003), SOAP Version 1.2 Part 1: Messaging Framework, World Wide Web Consortium."},{"key":"key2022032220214938100_b22","doi-asserted-by":"crossref","unstructured":"Hafner, M., Breu, R. and Weber, B. (2006), To appear in: Model Driven Security for Inter\u2010Organizational Workflows in E\u2010Governement, Idea Group, Inc., Hershey, PA.","DOI":"10.4018\/978-1-59904-138-4.ch014"},{"key":"key2022032220214938100_b21","doi-asserted-by":"crossref","unstructured":"Hafner, M., Breu, R., Breu, M. and Nowak, A. (2005), \u201cModeling inter\u2010organizational workflow security in a peer\u2010to\u2010peer environment\u201d, Proceedings of the International Conference on Web Services (ICWS 2005), Orland, FL, July 12\u201015.","DOI":"10.1109\/ICWS.2005.83"},{"key":"key2022032220214938100_b23","doi-asserted-by":"crossref","unstructured":"Huang, W.K. and Atluri, V. (1999), \u201cSecureFlow: a secure web\u2010enabled workflow management system\u201d, ACM Workshop on Role\u2010Based Access Control.","DOI":"10.1145\/319171.319179"},{"key":"key2022032220214938100_b24","unstructured":"Imamura, T. (2002), in Eastlake, D. and Reagle, J. (Eds), XML Encryption Syntax and Processing, W3C Recommendation, 10 December 2002, W3C."},{"key":"key2022032220214938100_b25","unstructured":"Kavantzas, N., Burdett, D., Ritzinger, G., Fletcher, T. and Lafon, Y. (2004), Web Services Choreography Description Language Version 1.0, World Wide Web Consortium."},{"key":"key2022032220214938100_b26","unstructured":"Mantell, K. (2003), From UML to BPEL, IBM\u2010developerWorks, available at: www\u2010106.ibm.com\/developerworks\/webservices\/library\/ws\u2010uml2bpel."},{"key":"key2022032220214938100_b27","doi-asserted-by":"crossref","unstructured":"Mendling, J. and Hafner, M. (2006), \u201cFrom inter\u2010organizational workflows to process execution: generating BPEL from WS\u2010CDL\u201d, Journal of Enterprise Information Management, forthcoming.","DOI":"10.1007\/11575863_70"},{"key":"key2022032220214938100_b28","unstructured":"Oasis (2005a) in Cantor, S., Kemp, J., Philpott, R. and Maler, E. (Eds), Assertions and Protocols for the OASIS Security Assertion Mark\u2010up Language (SAML) V2.0, OASIS."},{"key":"key2022032220214938100_b29","unstructured":"Oasis (2005b), in Anderson, A. (Ed.), Core and Hierarchical Role Based Access Control (RBAC) Profile of XACML v2.0, OASIS."},{"key":"key2022032220214938100_b30","unstructured":"Oasis (2005c) in Moses, T. and Godik, S. (Eds), eXtensible Access Control Mark\u2010up Language (XACML) TC Version 2.0, OASIS."},{"key":"key2022032220214938100_b31","unstructured":"Oracle (2006), Oracle BPEL Process Manager 10.1.2.0.2, Oracle."},{"key":"key2022032220214938100_b32","doi-asserted-by":"crossref","unstructured":"Sandhu, R. and Park, J.S. (1998), \u201cDecentralized user\u2010role assignment for web\u2010based intranets\u201d, Proceedings of 3rd ACM Workshop on Role\u2010Based Access Control, ACM, Fairfax, VA, pp. 1\u201012.","DOI":"10.1145\/286884.286887"},{"key":"key2022032220214938100_b33","doi-asserted-by":"crossref","unstructured":"Sandhu, R.S., Bhamidipati, V. and Munawer, Q. (1999), \u201cThe ARBAC97 model for role\u2010based administration of roles\u201d, ACM Transactions on Information and Systems Security (TISSEC), Vol. 1, pp. 105\u201035.","DOI":"10.1145\/300830.300839"},{"key":"key2022032220214938100_b34","doi-asserted-by":"crossref","unstructured":"Sandhu, R.S., Coynek, E.J., Feinsteink, H.L. and Youmank, C.E. (1995), \u201cRole\u2010based access control models\u201d, IEEE Computer, Vol. 29 No. 2.","DOI":"10.1109\/2.485845"},{"key":"key2022032220214938100_b35","unstructured":"Thompson, M., Johnson, W., Mudumbai, S., Hoo, G. and Hackson, K. (1999), \u201cCertificate\u2010based access control for widely distributed resources\u201d, paper presented at 8th USENIX Security Symposium."},{"key":"key2022032220214938100_b36","doi-asserted-by":"crossref","unstructured":"Wainer, J., Barthelmess, P. and Kumar, A. (2003), \u201cW\u2010RBACA \u2013 workflow security model incorporating controlled overriding of constraints\u201d, International Journal of Cooperative Information Systems, Vol. 12, pp. 455\u201085.","DOI":"10.1142\/S0218843003000814"},{"key":"key2022032220214938100_b37","doi-asserted-by":"crossref","unstructured":"Yag\u00fce, M. and Troya, J.M. (2002), \u201cA semantic approach for access control in web services\u201d, paper presented at Euroweb 2002 Conference, The Web and the GRID: from e\u2010science to e\u2010business, British Computer Society & World Wide Web Consortium.","DOI":"10.14236\/ewic\/EW2002.3"}],"container-title":["Internet Research"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/10662240610710978","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/10662240610710978\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/10662240610710978\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,24]],"date-time":"2025-07-24T23:40:10Z","timestamp":1753400410000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/intr\/article\/16\/5\/491-506\/186153"}},"subtitle":[],"editor":[{"given":"Mariemma","family":"Yague","sequence":"first","affiliation":[],"role":[{"role":"editor","vocabulary":"crossref"}]}],"short-title":[],"issued":{"date-parts":[[2006,10,1]]},"references-count":37,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2006,10,1]]}},"alternative-id":["10.1108\/10662240610710978"],"URL":"https:\/\/doi.org\/10.1108\/10662240610710978","relation":{},"ISSN":["1066-2243"],"issn-type":[{"value":"1066-2243","type":"print"}],"subject":[],"published":{"date-parts":[[2006,10,1]]}}}