Skip to search boxSkip to navigationSkip to main content

Goal-Equivalent Secure Business Process Re-engineering

  • Hugo Andrés Lópes Acosta
    ,
  • Fabio Massacci
    ,
  • Nicola Zannone
  • University of Trento
Research Output:
Journal Article or Conference Article in Journal
Conference article
Peer-review

Publication Information

Output type

Research Output:
Journal Article or Conference Article in Journal
Conference article
Peer-review

Original language

English

Pages from-to (Number of pages)

Pages 212-223

Journal (Volume, Issue Number)

Lecture Notes in Computer Science

Publication milestones

  • Published - 2008

Publication status

Published - 2008

ISSN

0302-9743

Abstract

The introduction of information technologies in health care systems often requires to re-engineer the business processes used to deliver care. Obviously, the new and re-engineered processes are observationally different and thus we cannot use existing model-based techniques to argue that they are somehow “equivalent”. In this paper we propose a method for passing from SI*, a modeling language for capturing and modeling functional, security, and trust organizational and system requirements, to business process specifications and vice versa. In particular, starting from an old secure business process, we reconstruct the functional and security requirements at organizational level that such a business process was supposed to meet (including the trust relations that existed among the members of the organization). To ensure that the re-engineered business process meets the elicited requirements, we employ a notion of equivalence based on goal-equivalence. Basically, we verify if the execution of the business process, described in terms of the trace it generates, satisfies the organizational model. We motivate and illustrate the method with an e-health case study.

Related Event

Title

ICSOC 2007 Workshops, International Workshops

Event type

Conference

Date

17/09/2007 - 17/09/2007

Location

WiennaAustria