Towards a UML 2.0 Profile for RBAC Modeling in Activity Diagrams

Alfonso Rodríguez, Eduardo Fernández-Medina, Mario Piattini


Business Processes are a crucial issue for many companies because they are the key to maintain competitiveness. Moreover, business processes are important for software developers, since they can capture from them the necessary requirements for software design and creation. Besides, business process modeling is the center for conducting and improving how the business is operated. Security is important for business performance, but traditionally, it is considered after the business processes definition. Empirical studies show that, at the business process level, customers, end users, and business analysts are able to express their security needs. In this work, we will present a proposal aimed at integrating security requirements and role identification for RBAC, through business process modeling. We will summarize our UML 2.0 profile for modeling secure business process through activity diagrams, and we will apply this approach to a typical health-care business process.


