IP Library Patent Application 12483889
Patent Application
App. No. 12/483,889

SECURITY ASPECTS OF SOA

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/483,889
Abstract

The present description refers in particular to a computer implemented method, computer program product, and computer system for dynamic separation of duties (SoD) during workflow execution. Based on at least one policy file, at a monitoring module, at least one node to be logged from a message in a message pipe of one or more messages exchanged when executing a workflow instance may be specified. Information on the at least one logged node may be passed to an enforcer. SoD violation for the at least one logged node may be checked at the enforcer. If, for the at least one logged node, SoD is violated, action may be taken based on the at least one policy file.

Claims (42)

1 . A computer-implemented method for dynamic separation of duties (SoD) during workflow execution, the method comprising:

specifying at a monitoring module, based on at least one policy file, at least one node to be logged from a message in a message pipe of one or more messages exchanged when executing a workflow instance;

passing information on the at least one logged node to an enforcer;

checking SoD violation for the at least one logged node at the enforcer; and

if for the at least one logged node SoD is violated, acting based on the at least one policy file.

2 . The method according to claim 1 , wherein checking SoD violation further comprises:

checking SoD violation by looking at history information of the workflow instance and verifying whether at least one logged node from one or more previous messages corresponding to the workflow instance relate to the same content as the at least one logged node.

3 . The method according to claim 1 , wherein acting based on the at least one policy file further comprises:

if a behavior of the at least one logged node is set to ‘active’, triggering termination of execution of the workflow instance; and/or

storing the at least one node for which SoD is violated in a log file and setting the behavior for the at least one node to ‘passive’ in the at least one policy file.

4 . The method according to claim 1 , wherein the at least one node is logged using a pair comprising a namespace and a nodename.

5 . The method according to claim 1 , wherein the monitoring module and the enforcer are deployed in a workflow management system executing the workflow instance.

6 . The method according to claim 1 , wherein the monitoring module is placed within a stack processing the message pipe as a handler.

7 . The method according to claim 1 , wherein the monitoring module and the enforcer are located on a server side of a distributed architecture.

8 . A computer system for dynamic separation of duties (SoD) during workflow execution, the system including instructions recorded on a computer-readable medium, the system comprising:

a monitoring module configured to:

specify based on at least one policy file at least one node to be logged from a message in a message pipe of one or more messages exchanged when executing a workflow instance; and

pass information on the at least one logged node to an enforcer;

wherein the enforcer is configured to:

check SoD violation for the at least one logged node; and

act based on the at least one policy file, if for the at least one logged node SoD is violated.

9 . The system according to claim 8 , wherein the enforcer is further operable to:

check SoD violation including looking at history information of the workflow instance and verifying whether at least one logged node from one or more previous messages corresponding to the workflow instance relate to the same content as the at least one logged node.

10 . The system according to claim 8 , wherein the enforcer is further configured to act based on the at least one policy file including:

triggering termination of execution of the workflow instance, if a behavior of the at least one logged node is set to ‘active’; and/or

storing the at least one node for which SoD is violated in a log file and setting the behavior for the at least one node to ‘passive’ in the at least one policy file.

11 . The system according to claim 8 , wherein the at least one node is logged using a pair comprising a namespace and a nodename.

12 . The system according to claim 8 , wherein the monitoring module and the enforcer are deployed in a workflow management system executing the workflow instance.

13 . The system according to claim 8 , wherein the monitoring module is placed within a stack processing the message pipe as a handler.

14 . The system according to claim 8 , wherein the monitoring module and the enforcer are placed on a server side of a distributed architecture.

15 . Computer program product comprising computer readable instructions, which when loaded and run in a computer and/or computer network system, causes the computer system and/or the computer network system to:

specify at a monitoring module, based on at least one policy file, at least one node to be logged from a message in a message pipe of one or more messages exchanged when executing a workflow instance;

pass information on the at least one logged node to an enforcer;

check SoD violation for the at least one logged node at the enforcer; and

if for the at least one logged node SoD is violated, act based on the at least one policy file.

16 . The computer program product of claim 15 wherein SoD violation is checked by looking at history information of the workflow instance and verifying whether at least one logged node from one or more previous messages corresponding to the workflow instance relate to the same content as the at least one logged node.

17 . The computer program product of claim 15 , wherein action based on the at least one policy file includes:

if a behavior of the at least one logged node is set to ‘active’, triggering termination of execution of the workflow instance; and/or

storing the at least one node for which SoD is violated in a log file and setting the behavior for the at least one node to ‘passive’ in the at least one policy file.

18 . The computer program product of claim 15 , wherein the at least one node is logged using a pair comprising a namespace and a nodename.

19 . The computer program product of claim 15 , wherein the monitoring module and the enforcer are deployed in a workflow management system executing the workflow instance.

20 . The computer program product of claim 15 , wherein the monitoring module is placed within a stack processing the message pipe as a handler.

Assignments (2)
CHANGE OF NAME Recorded Aug 26, 2014
From: SAP AG
To: SAP SE
Reel/Frame 033625/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2009
From: BENAMEUR, AZZEDINE; KHOURY, PAUL EL; TRINDADE, JOANA DA
To: SAP AG
Reel/Frame 023251/0514 →