论文部分内容阅读
Information leak, which can undermine the compliance of web-service-composition business processes for some policies, is one of the major conces in web service composition. We present an automated and effective approach for the detection of implicit information leaks in business process execution language (BPEL) based on information fl ow analysis. We introduce an adequate meta-model for BPEL representation based on a Petri net for transformation and analysis. Building on the concept of Petri net place-based noninterference, the core contribution of this paper is the application of a Petri net reachability graph to estimate Petri net interference and thereby to detect implicit information leaks in web service composition. In addition, a case study illustrates the application of the approach on a concrete workfl ow in BPEL notation.