<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Compliance to data protection and purpose control using process mining technique</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>Eindhoven University of Technology</institution>
          ,
          <country country="NL">the Netherlands</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>The business processes of an organisation are executed in certain boundaries. Some of the restrictions are raised from the environment of the organisations such as regulatory and supervisory constraints. One of the regulations that is imposed on organisations is the European General Data Protection Regulation (GDPR). The most important aspect of the GDPR rules is how organisations handle personal data of their customers. In this research, we focus on this aspect of the GDPR. Our goal is to develop a solution that enables organisations to deal with the challenges of becoming compliant with GDPR. We plan to use and improve process mining techniques to tackle the problems such as discovering data- ow and control- ow of business processes that have interaction with personal data of customers. Our approach consists of four phases: (1) discover process model based on purpose, (2) translate regulatory rules to technical rules, (3) develop privacy policy model base on the GDPR, (4) conformance analysis.</p>
      </abstract>
      <kwd-group>
        <kwd>Process Mining GDPR Compliance Checking</kwd>
        <kwd>Rule Trans- lation</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        Generally, business processes of an organisation are executed in certain
boundaries. These restrictions are de ned by a set of business rules. Some of these
rules are regulatory and supervisory constraints, some are based on the domain
standards, some are implemented according to the internal regulations of each
organisation and many are de ned by the trading partners [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ]. The complexity
of the organisation processes, thus, has increased signi cantly and there is need
for constant monitoring of the implementation and execution of these complex
processes and assessment of their conformance with business rules. Given the
issues raised, organisations face major challenges. They must manage complex
organisational and cross-organisational processes, monitor running processes and
examine conformance with all business rules de ned by managers, governments
and stakeholders [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. One of the regulations that is imposed on organisations is
the European General Data Protection Regulation (GDPR) [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. The most
important aspect of the GDPR rules is how organisations handle personal data of
their customers, in which \the purpose of using data by organisation" and \the
consent of the customer" have more prominent roles. New and improved rights
for the customer, such as \the right to be forgotten", impacts companies because
such rights need to be accommodated in their internal processes. In this work
we focus on these important aspects of GDPR and address the most important
challenges that companies may face to become compliant:
      </p>
      <p>
        Most organisations rarely have a global picture and knowledge about
the data- ow between their business processes. Therefore, they cannot nd the
points of the whole process that need improvement to become compliant with
the GDPR [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
      </p>
      <p>
        For auditing or internal assessment of their processes, organisations need
to identify which process activities interact with personal data of the customers.
At the next step, they require a mechanism to distinguish between personal
data and other information [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. Furthermore, they should investigate whether
the data is used for the intended purpose [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ].
      </p>
      <p>
        Organisations should handle their processes in such way to allow users
to consent to some, but not all processes [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. To this end, they should clearly
state their privacy policy, the purpose of collecting and using the data. This
can only be done when the organisation itself has a clear view of data- ow and
control- ow of its processes in reality.
      </p>
      <p>Organisations should track the consent of their customers. Revoking the
consent has impacts on the execution of the activities that use personal data.
On the one hand, current process cannot use the data and on the other hand,
processes that may be run in the future might not be able to use the data
of those group of customers. For this reason, organisations require to identify
the processes that are associated with personal data at the runtime. We are
investigating the challenges and we aim to concentrate on developing solutions
to deal with the mentioned challenges. We plan to use and improve process
mining techniques to tackle the problems such as discover the data- ow and
control- ow of business processes that have interaction with personal data of
customers. Our goal is to develop a mechanism to translate regulatory rules(in
this work GDPR rule set) into technical rules and model GDPR compliance rule
set as patterns. Finally, we plan to use conformance techniques to assess whether
the discovered process model is complied with GDPR compliance rule.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Approach and related work</title>
      <p>Our overall goal is to provide a framework for checking compliance with data
protection and purpose control using process mining techniques. To implement
the solution, our approach consists of four main steps(Fig.1):</p>
      <p>
        1. Discover process model based on purpose: Usually, process mining
is performed to discover, monitor and improve real processes (not assumed or
modeled processes) and is based on the knowledge extracted from the event
logs of information systems [
        <xref ref-type="bibr" rid="ref12 ref4">12, 4</xref>
        ]. Typically, there is a gap between a modeled
process and the trend expected to occur in the process run and what occurs in
reality. The goal of process mining is to identify and decrease problems caused
by these deviations. Process mining techniques and algorithms are categorized
as three main types including discovery, conformance, and extension [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. Process
discovery is the most common process mining technique and can automatically
detect and generate a process model based on the event log and reality [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. We
have a plan to continue and improve the discovery technique of \Object-Centric
Process Mining" [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. In[
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], a modeling language which combines data models
with declarative models to discover an object-centric behavioral constraint model
was proposed. The goal of this study was to discover a process model from the log
where the scope is data/object-centric processes supported by CRM and ERP
systems. Since customer is a basic concept in designing such systems,initially by
considering structured data model, we aim to use their approach to nd in which
parts of the process execution there are interactions with customer data. In the
next step, we intend to extend their algorithm and add purpose speci cation
to the core part of it. In [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], although the approach is capable to nd the
intersection points between the process layer and data layer, it cannot discover
the purpose of this association. In this research, we aim to cover this gap.
      </p>
      <p>2. Translate regulatory rules to technical rules: A fundamental step
towards the solution is regulatory analysis to develop a concrete understanding
of the underlying business needs. This analysis must be done from two points
of view: the regulations on data protection, particularly the GDPR, and the
business needs for facilitating compliance thereof. Regarding to our goals, policies
that should be formalized as a rule include concepts such as the data ground
under which personal data falls, roles of the entities requesting and processing
personal data, operations and services performed over personal data, attributes
of all the involved entities, purposes of requesting/processing data. Therefore,
having the regulatory analysis as the starting point, generalization and creation
of an abstract model of privacy policy base on the GDPR comes next.</p>
      <p>
        3. Develop privacy policy model base on the GDPR: To check
compliance of the log with GDPR, at rst we should translate the GDPR rule set
to patterns. There are two basic types of compliance checking: forward and
backward compliance checking [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. At this phase we plan to focus on
backward compliance checking based on event data. Backward compliance checking
assesses compliance between process executions and all compliance rules, the
result will show when and where a particular rule was violated. A variety of
conformance checking techniques have been proposed based on an event log and
process model (e.g., Petri-net) [
        <xref ref-type="bibr" rid="ref16 ref5 ref6 ref8">5, 6, 8, 16</xref>
        ]. [
        <xref ref-type="bibr" rid="ref1 ref11">1, 11</xref>
        ] proposed approaches based on
temporal logic. In [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ], the authors provide Petri-net patterns modeling typical
compliance rules. These rules can be instantiated for a particular process, i.e.,
the abstract activities in the pattern are replaced by concrete activities recorded
in the event log. The log complies to the rule if each log trace is described by the
Petrinet pattern. In case a trace is not described, they locate where the trace
deviates from the pattern. In this work, they focus on compliance with control- ow.
As our nal goal is checking compliance of discovered models with GDPR, to this
end, similarly to the work [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ], we intend to model and generalize the mentioned
aspect of the GDPR as an abstract process model. We realized that this model
should include and concern two concepts of \the purpose of each activity" -that
can be one of the followings: (DC) Data collection,(DU) data usage,(NA) none
of them or (DC/DU) both of them- and \the consent of the customer". Since
the OCBC model is based on the declarative process model, we cannot use their
idea to generalize and model the GDPR rule set as Petri net models. In their
work, they focus on compliance to control- ow whereas in our work we require
to concentrate on compliance to data- ow more than control- ow.
      </p>
      <p>
        4. Conformance analysis: In conformance checking, an existing model
is compared with the model discovered from the event log. The goal of this
technique is to assess whether a process model discovered from the log conforms
to the assumed and predetermined process. This technique can be applied to
di erent aspects of the process, such as for an ideal process model, organisational
vision and business rules and policies [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. In this phase, we will use this technique
to check the compliance of business process with the GDPR.
3
      </p>
    </sec>
    <sec id="sec-3">
      <title>Conclusion</title>
      <p>In this paper, we mentioned the most important challenges that organisations
meet to become compliant with the GDPR. We de ned our goals and the scope
that we plan to concentrate on. We outlined our research plan to provide a
framework for checking compliance to data protection and purpose control using
process mining techniques. Besides explaining each phase of our approach, we
summarized the related works and techniques that we intend to use or extend
at our future plan for the implementation of each phase.</p>
    </sec>
    <sec id="sec-4">
      <title>Acknowledgment</title>
      <p>The author has received funding within the BPR4GDPR project from the
European Union's Horizon 2020 research and innovation programme under grant
agreement No 787149.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>van der Aalst</surname>
          </string-name>
          , W.M.P., de Beer, H.T.,
          <string-name>
            <surname>van Dongen</surname>
            ,
            <given-names>B.F.</given-names>
          </string-name>
          :
          <article-title>Process mining and veri cation of properties: An approach based on temporal logic</article-title>
          . In: Meersman,
          <string-name>
            <given-names>R.</given-names>
            ,
            <surname>Tari</surname>
          </string-name>
          ,
          <string-name>
            <surname>Z</surname>
          </string-name>
          . (eds.)
          <article-title>On the Move to Meaningful Internet Systems 2005: CoopIS, DOA, and ODBASE</article-title>
          . pp.
          <volume>130</volume>
          {
          <fpage>147</fpage>
          . Springer Berlin Heidelberg, Berlin, Heidelberg (
          <year>2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>van der Aalst</surname>
            ,
            <given-names>W.M.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schmiedel</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Extracting Event Data from Databases to Unleash Process Mining</article-title>
          , pp.
          <volume>105</volume>
          {
          <fpage>128</fpage>
          . Springer International Publishing,
          <string-name>
            <surname>Cham</surname>
          </string-name>
          (
          <year>2015</year>
          ). https://doi.org/10.1007/978-3-
          <fpage>319</fpage>
          -14430-6 8, https://doi.org/10.1007/978-3-
          <fpage>319</fpage>
          -14430-6 8
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Van der Aalst</surname>
          </string-name>
          , W.: Process Mining: Discovery, Conformance and Enhancement of Business Processes. Springer, Verlag Berlin Heidelberg (
          <year>2011</year>
          ). https://doi.org/10.1007/978-3-
          <fpage>662</fpage>
          -49851-4, https://doi.org/10.1007/978-3-
          <fpage>662</fpage>
          -49851-4
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Van der Aalst</surname>
          </string-name>
          , W.: Data Science in Action. Springer, Verlag Berlin Heidelberg (
          <year>2016</year>
          ). https://doi.org/10.1007/978-3-
          <fpage>642</fpage>
          -19345-3, https://doi.org/10.1007/978- 3-
          <fpage>642</fpage>
          -19345-3
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Aalst</surname>
            , van der,
            <given-names>W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Adriansyah</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dongen</surname>
            , van,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>Replaying history on process models for conformance checking and performance analysis</article-title>
          .
          <source>WIREs Data Mining and Knowledge Discovery</source>
          <volume>2</volume>
          (
          <issue>2</issue>
          ),
          <volume>182</volume>
          {
          <fpage>192</fpage>
          (
          <year>2012</year>
          ). https://doi.org/10.1002/widm.1045
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Adriansyah</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dongen</surname>
            , van,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Aalst</surname>
          </string-name>
          , van der, W.:
          <article-title>Conformance checking using cost-based tness analysis</article-title>
          . In: Chi,
          <string-name>
            <given-names>C.</given-names>
            ,
            <surname>Johnson</surname>
          </string-name>
          , P. (eds.)
          <source>Proceedings of the 15th IEEE International Conference on Enterprise Distributed Object Computing (EDOC</source>
          <year>2011</year>
          , Helsinki, Finland,
          <source>August 29-September 2</source>
          ,
          <year>2011</year>
          ). pp.
          <volume>55</volume>
          {
          <fpage>64</fpage>
          .
          <article-title>Institute of Electrical and Electronics Engineers (IEEE), United States (</article-title>
          <year>2011</year>
          ). https://doi.org/10.1109/EDOC.
          <year>2011</year>
          .12
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Basin</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Debois</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hildebrandt</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>On purpose and by necessity: compliance under the gdpr</article-title>
          .
          <source>In: Business Process Management. Financial Cryptography and Data Security</source>
          , Nieuwport, Curacao (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Calders</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          , Gunther,
          <string-name>
            <given-names>C.W.</given-names>
            ,
            <surname>Pechenizkiy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            ,
            <surname>Rozinat</surname>
          </string-name>
          ,
          <string-name>
            <surname>A.</surname>
          </string-name>
          :
          <article-title>Using minimum description length for process mining</article-title>
          .
          <source>In: Proceedings of the 2009 ACM symposium on Applied Computing (SAC'09)</source>
          . pp.
          <volume>1451</volume>
          {
          <fpage>1455</fpage>
          . ACM Press (
          <year>2009</year>
          ). https://doi.org/http://doi.acm.
          <source>org/10</source>
          .1145/1529282.1529606
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9. of the European Union,
          <string-name>
            <given-names>C.</given-names>
            ,
            <surname>Parliament</surname>
          </string-name>
          , E.:
          <article-title>Regulation (eu) 2016/679 of the european parliament and of the council of 27 april 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data</article-title>
          ,
          <source>and repealing directive</source>
          <volume>95</volume>
          /46/ec (general
          <source>data protection regulation)</source>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Li</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          , de Carvalho, R., van der Aalst, W.:
          <article-title>Automatic discovery of object-centric behavioral constraint models</article-title>
          . In: Abramowicz,
          <string-name>
            <surname>W</surname>
          </string-name>
          . (ed.)
          <source>Business Information Systems</source>
          . pp.
          <volume>43</volume>
          {
          <fpage>58</fpage>
          . Lecture Notes in Business Information Processing, Springer, Germany (6
          <year>2017</year>
          ). https://doi.org/10.1007/978-3-
          <fpage>319</fpage>
          -59336-4 4
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Montali</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pesic</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Aalst</surname>
            ,
            <given-names>W.M.P.</given-names>
          </string-name>
          v.d.,
          <string-name>
            <surname>Chesani</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mello</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Storari</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Declarative speci cation and veri cation of service choreographiess</article-title>
          .
          <source>ACM Trans. Web</source>
          <volume>4</volume>
          (
          <issue>1</issue>
          ), 3:
          <issue>1</issue>
          {3:
          <fpage>62</fpage>
          (Jan
          <year>2010</year>
          ). https://doi.org/10.1145/1658373.1658376, http://doi.acm.
          <source>org/10</source>
          .1145/1658373.1658376
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>de Murillas</surname>
          </string-name>
          , E.G.L.,
          <string-name>
            <surname>van der Aalst</surname>
            ,
            <given-names>W.M.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Reijers</surname>
            ,
            <given-names>H.A.</given-names>
          </string-name>
          :
          <article-title>Process mining on databases: Unearthing historical data from redo logs</article-title>
          . In: Motahari-Nezhad,
          <string-name>
            <given-names>H.R.</given-names>
            ,
            <surname>Recker</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            ,
            <surname>Weidlich</surname>
          </string-name>
          , M. (eds.) Business Process Management. pp.
          <volume>367</volume>
          {
          <fpage>385</fpage>
          . Springer International Publishing,
          <string-name>
            <surname>Cham</surname>
          </string-name>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Petkovic</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Prandi</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zannone</surname>
          </string-name>
          , N.:
          <article-title>Purpose control: Did you process the data for the intended purpose</article-title>
          ? In: Jonker,
          <string-name>
            <given-names>W.</given-names>
            ,
            <surname>Petkovic</surname>
          </string-name>
          , M. (eds.)
          <article-title>Secure Data Management</article-title>
          . pp.
          <volume>145</volume>
          {
          <fpage>168</fpage>
          . Springer Berlin Heidelberg, Berlin, Heidelberg (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Ramezani</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fahland</surname>
            , D., van der Aalst,
            <given-names>W.M.P.</given-names>
          </string-name>
          :
          <article-title>Where did i misbehave? diagnostic information in compliance checking</article-title>
          . In: Barros,
          <string-name>
            <given-names>A.</given-names>
            ,
            <surname>Gal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            ,
            <surname>Kindler</surname>
          </string-name>
          , E. (eds.) Business Process Management. pp.
          <volume>262</volume>
          {
          <fpage>278</fpage>
          . Springer Berlin Heidelberg, Berlin, Heidelberg (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <given-names>Ramezani</given-names>
            <surname>Taghiabadi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            ,
            <surname>Fahland</surname>
          </string-name>
          , D., van Dongen,
          <string-name>
            <given-names>B.F.</given-names>
            ,
            <surname>van der Aalst</surname>
          </string-name>
          ,
          <string-name>
            <surname>W.M.P.</surname>
          </string-name>
          :
          <article-title>Diagnostic information for compliance checking of temporal compliance requirements</article-title>
          . In: Salinesi,
          <string-name>
            <given-names>C.</given-names>
            ,
            <surname>Norrie</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.C.</given-names>
            ,
            <surname>Pastor</surname>
          </string-name>
          ,
          <string-name>
            <surname>O</surname>
          </string-name>
          . (eds.)
          <source>Advanced Information Systems Engineering</source>
          . pp.
          <volume>304</volume>
          {
          <fpage>320</fpage>
          . Springer Berlin Heidelberg, Berlin, Heidelberg (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Rozinat</surname>
          </string-name>
          , A.,
          <string-name>
            <surname>van der Aalst</surname>
            ,
            <given-names>W.M.P.</given-names>
          </string-name>
          :
          <article-title>Conformance checking of processes based on monitoring real behavior</article-title>
          .
          <source>Inf. Syst</source>
          .
          <volume>33</volume>
          (
          <issue>1</issue>
          ),
          <volume>64</volume>
          {95 (Mar
          <year>2008</year>
          ). https://doi.org/10.1016/j.is.
          <year>2007</year>
          .
          <volume>07</volume>
          .001, http://dx.doi.org/10.1016/j.is.
          <year>2007</year>
          .
          <volume>07</volume>
          .001
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Skopik</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schall</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dustdar</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Modeling and Mining of Dynamic Trust in Complex Service-Oriented Systems</article-title>
          , pp.
          <volume>29</volume>
          {
          <fpage>75</fpage>
          . Springer Vienna, Vienna (
          <year>2011</year>
          ), https://doi.org/10.1007/978-3-
          <fpage>7091</fpage>
          -0813-03
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>