Siani Pearson, P. Rao, T. Sander, A. Parry, Allan Paull, Satish Patruni, Venkata Dandamudi-Ratnakar, Pranav Sharma
{"title":"Scalable, accountable privacy management for large organizations","authors":"Siani Pearson, P. Rao, T. Sander, A. Parry, Allan Paull, Satish Patruni, Venkata Dandamudi-Ratnakar, Pranav Sharma","doi":"10.1109/EDOCW.2009.5331996","DOIUrl":"https://doi.org/10.1109/EDOCW.2009.5331996","url":null,"abstract":"Accountability is emerging as an important theme within the regulatory privacy community. For global corporations, demonstrating accountability is no easy task due to the potentially large number of projects that have privacy sensitive aspects, privacy oversight being a mostly manual process and privacy staff typically being small. So how can a company present proof points that its projects comply with its privacy promises and obligations? In this paper we address this problem by introducing a technology-based solution for scalable, accountable privacy management across an organization. We present an Accountability Model Tool (AMT) that addresses the problem of capturing data about business processes in order to determine their privacy compliance. AMT utilizes an intelligent questionnaire with good completeness properties and is based on an augmented rule engine.","PeriodicalId":226791,"journal":{"name":"2009 13th Enterprise Distributed Object Computing Conference Workshops","volume":"73 4 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2009-11-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"114392388","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Idea to derive security policies from collaborative business processes","authors":"Ji Hu","doi":"10.1109/EDOCW.2009.5331987","DOIUrl":"https://doi.org/10.1109/EDOCW.2009.5331987","url":null,"abstract":"Collaborative business processes often consist of services provided by multiple business entities which agree to join a business collaboration. To enable trustworthy and secure consumption and provisioning of services across organizational boundaries, security requirements must be carefully defined so as to be coherent, consistent, and in compliance with designed business processes. However, managing security requirements in collaborative environments is error-prone, effort inefficient, and hard to be verified. This paper introduces our ongoing research effort for developing algorithms and methods to derive security policies from formally defined business process models. The derived policies serve as templates which can be later on complemented with concrete business entity data and finally turned into deployable policies.","PeriodicalId":226791,"journal":{"name":"2009 13th Enterprise Distributed Object Computing Conference Workshops","volume":"158 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2009-11-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"124495128","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Business service identification and modelling with context support","authors":"Espen Moeller, Arne-Jørgen Berre","doi":"10.1109/EDOCW.2009.5331978","DOIUrl":"https://doi.org/10.1109/EDOCW.2009.5331978","url":null,"abstract":"Current approaches for service-oriented architecture (SOA) do not fully recognize and align the notion of business as a service. While motivation, value creation and outsourcing are primary concerns in the business domain, componentization is an important paradigm in the software domain. Using the service metaphor to describe concerns in both domains can lead to confusion. PROSERVE is developed as an approach, based on a service context scheme and service trees, to overcome the shortcomings of existing service modelling frameworks. By providing a matrix for how different types of participants can interact within and across domains, rules can be derived for extracting context-views and context-interaction for services. Moreover, a service tree can be used as a visual metaphor for selective abstraction, allowing details to be toggled in the context they exist in. A prototype support tool, based on the PROSERVE metamodel, provides proof of concepts for context-supported service modelling.","PeriodicalId":226791,"journal":{"name":"2009 13th Enterprise Distributed Object Computing Conference Workshops","volume":"12 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2009-11-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"124895655","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Vocabularies, ontologies and rules for the enterprise","authors":"Jens Dietrich, D. Gašević","doi":"10.1109/EDOCW.2009.5331983","DOIUrl":"https://doi.org/10.1109/EDOCW.2009.5331983","url":null,"abstract":"This paper gives a brief overview of the international workshop on vocabularies, ontologies and rules in the enterprise held at the EDOC 2009 conference. The paper discusses the scope and key topics of the workshop, reflects on the program of the workshop, including, the keynote and papers accepted for presentation.","PeriodicalId":226791,"journal":{"name":"2009 13th Enterprise Distributed Object Computing Conference Workshops","volume":"18 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2009-11-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"122174842","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Document Logic: Risk analysis of business processes through document authenticity","authors":"S. Iida, G. Denker, C. Talcott","doi":"10.1109/EDOCW.2009.5332014","DOIUrl":"https://doi.org/10.1109/EDOCW.2009.5332014","url":null,"abstract":"Document Logic is a simple yet powerful framework to infer risks in business processes. We focus on flows of documents and build a set of inference rules based on document authenticity and a simple trust model. We have built a prototype of a system that checks document authenticity in Maude. Maude is an implementation of rewriting logic. Rewriting logic is expressive and general enough to define other specialized logics, like Document Logic. In our framework, a business process is modeled as a transition system. Our prototype takes a business process and an undesired situation as its input and outputs all the possible risks in the business process.","PeriodicalId":226791,"journal":{"name":"2009 13th Enterprise Distributed Object Computing Conference Workshops","volume":"31 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2009-11-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"121068159","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Modeling and reconfiguration of critical business processes for the purpose of a Business Continuity Management respecting security, risk and compliance requirements at Credit Suisse using algebraic graph transformation","authors":"Christoph Brandt, F. Hermann, T. Engel","doi":"10.1109/EDOCW.2009.5332015","DOIUrl":"https://doi.org/10.1109/EDOCW.2009.5332015","url":null,"abstract":"Critical business processes can fail. Therefore, continuity processes are needed as backup solutions. At the same time business processes are required to comply with security, risk and compliance requirements. In the context discussed here, they should be modeled in a decentralized, local and declarative way, including methodological support by tools. By discussing a simplified loan granting process in the context of a Business Continuity Management System at Credit Suisse, we show how algebraic graph transformation can contribute a methodologically sound solution being compatible with all these requirements in a coherent way. As a consequence significant benefits of automation and quality can be realized. The presented contribution is theoretically sound and implementable by the people in the field.","PeriodicalId":226791,"journal":{"name":"2009 13th Enterprise Distributed Object Computing Conference Workshops","volume":"1 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2009-11-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"129542554","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Performance modelling power consumption and carbon emissions for Server Virtualization of Service Oriented Architectures (SOAs)","authors":"P. Brebner, L. O'Brien, Jon Gray","doi":"10.1109/EDOCW.2009.5332010","DOIUrl":"https://doi.org/10.1109/EDOCW.2009.5332010","url":null,"abstract":"Server Virtualization is driven by the goal of reducing the total number of physical servers in an organisation by consolidating multiple applications on shared servers. Expected benefits include more efficient server utilisation, and a decrease in green house gas emissions. However, Service Oriented Architectures combined with Server Virtualization may significantly increase risks such as saturation and Service Level Agreement (SLA) violations.","PeriodicalId":226791,"journal":{"name":"2009 13th Enterprise Distributed Object Computing Conference Workshops","volume":"11 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2009-11-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"116798229","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Database synchronization as a service","authors":"C. Lutteroth, Gerald Weber","doi":"10.1109/EDOCW.2009.5332009","DOIUrl":"https://doi.org/10.1109/EDOCW.2009.5332009","url":null,"abstract":"Many distributed applications require the ability to synchronize databases over a network. Using a service oriented architecture, this poses challenges with regard to the way change information is expressed and merged. We propose a solution for a database synchronization service that is transactional, idempotent and reduces merging conflicts to a minimum. The PDStore system enables fine-grained recording of database changes and incremental synchronization, transmitting only as much data as necessary. Data instances are identified with globally unique identifiers, thus avoiding name clashes and reducing merging conflicts. Merging conflicts do not disturb the integrity of the database and can be resolved later. The approach presented in this paper is used in a municipal database system for earthquake safety assessment data of buildings.","PeriodicalId":226791,"journal":{"name":"2009 13th Enterprise Distributed Object Computing Conference Workshops","volume":"43 7","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2009-11-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"114126155","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
F. M. Pérez, V. Gilart-Iglesias, Antonio Ferrándiz-Colmeiro, J. Berná-Martínez, Jorge Gea-Martínez
{"title":"New models of agile manufacturing assisted by semantic","authors":"F. M. Pérez, V. Gilart-Iglesias, Antonio Ferrándiz-Colmeiro, J. Berná-Martínez, Jorge Gea-Martínez","doi":"10.1109/EDOCW.2009.5331976","DOIUrl":"https://doi.org/10.1109/EDOCW.2009.5331976","url":null,"abstract":"This paper proposesa process management system that enables new dynamic manufacturing models to be implemented. This system facilitates the automation of process modelling, thus reducing the workload for process engineers. To this end, it focuses on the incorporation of knowledge in the definition of the processes and services involved. The document presents a general scenario in which industrial machinery is offered as services (IMaaS), integrated under a Service-oriented Architecture (SOA); this is followed by a definition of an ontology that enables the incorpoation of knowledge into the proposed scenario; finally the implementation of a prototype, along with a test scenario, is presented, enabling the viability of the proposal to be demonstrated.","PeriodicalId":226791,"journal":{"name":"2009 13th Enterprise Distributed Object Computing Conference Workshops","volume":"67 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2009-11-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"126001117","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Gap analysis of application landscapes","authors":"M. Postina, Igor Sechyn, U. Steffens","doi":"10.1109/EDOCW.2009.5331980","DOIUrl":"https://doi.org/10.1109/EDOCW.2009.5331980","url":null,"abstract":"For many enterprises the introduction of service orientation is still a daunting task and there is often no distinct idea of how to approach respective projects. Only recently, SOA research addresses this open and essential question and systematic methodologies for SOA introduction and evolution have been conceived. IBM's SOMA and sd&m's Quasar Enterprise are prominent examples. In practice, these methodologies have to rely on a variety of enterprise-specific information and integrate a number of different architectural instruments. This contribution introduces one typical constituent of evolution towards service orientation making extensive use of enterprise-specific information. The presented approach and prototypical implementation for the gap analysis of current and ideal application landscapes can also be regarded as a building block for more general architecture development methodologies like for example proposed by the TOGAF Architecture Development Method. The gap analysis measures the distance between two states of the application landscape by applying and aggregating a set of metrics specifically aimed at the context of architecture development. It results in a list of concrete actions which can be considered for landscape migration planning and hence can be a helpful instrument for enterprise architects.","PeriodicalId":226791,"journal":{"name":"2009 13th Enterprise Distributed Object Computing Conference Workshops","volume":"44 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2009-11-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"124837631","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}