Workflow Control Task for Automated Security Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current workflow control systems in collaborative environments, such as Virtual Organizations, face challenges in managing complex security and trust requirements across geographically dispersed partners, requiring rigid and manual authorization processes that lack flexibility and automation.
Innovation Solution
A computer system with a process modelling unit that defines a process model with control tasks to enforce control aspects, utilizing a service layer for dynamic control service invocation, enabling flexible and automated management of trust, security, and contract compliance through a control context and extension roles.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Manufacturing precision
If manual authorization processes are used to manage security and trust requirements, then control precision is improved, but device complexity and ease of operation deteriorate
Solution Approach 1:
The workflow engine automatically performs authorization checks and control aspect verification without requiring manual programmer intervention. The system self-manages security policies, trust verification, and contract compliance monitoring through automated service invocations, eliminating the need for manual authorization process management while maintaining precise control.
Solution Approach 2:
The control task serves multiple functions: it invokes control services, enforces control aspects, verifies trust levels, checks security policies, and monitors contract compliance. This multi-functional approach consolidates what would otherwise require separate manual processes into a single automated task, reducing overall process complexity while maintaining comprehensive control precision.
2Reliability
If rigid manual authorization processes are used, then reliability is improved through explicit control, but adaptability and productivity deteriorate
Solution Approach 1:
The authorization process transitions from rigid manual procedures to dynamic automated service invocations. The control task can adaptively invoke different control services based on runtime conditions, process context, and specific control aspects required. This dynamic approach maintains reliability through automated verification while enabling flexibility in handling diverse collaboration scenarios.
Solution Approach 2:
The control task acts as an intermediary between the workflow process and control services. It dynamically determines which control services to invoke and manages the interaction between process execution and security/trust/contract verification mechanisms. This intermediary role enables flexible adaptation to different control requirements while maintaining reliable automated enforcement.
3Productivity
If automated control services are introduced, then productivity and adaptability are improved, but device complexity increases
Solution Approach 1:
The control task serves as an intermediary layer between the workflow engine and control services, abstracting the complexity of service invocation and management. This intermediary structure allows the workflow process to remain simple while enabling sophisticated automated control through the control task's service coordination capabilities.
Solution Approach 2:
The control task is designed as a universal, multi-functional component that can handle various control aspects (security, trust, contracts) through a single standardized mechanism. This universal approach avoids the need for separate complex structures for each control function, thereby improving productivity through automation while limiting the increase in system complexity.
Data Source
AI summary
A computer system, method and computer program for controlling a workflow process. A process modeling unit is configured to define a process model with at least a first task and a second task, wherein the second task needs to comply with a control aspect and depends on the first task, and is further configured to insert into the process model a control task between the first and the second task, wherein the control task is configured to enforce the control aspect on the second task by using a control service of a subsystem. A process execution unit of the system is configured to generate a process instance from the process model and to instantiate a control context to capture the current state of the process instance, the control context being used by an instance of the control task to invoke the control service according to the control aspect.


