Tuesday, 3 May 2011

What is Trust?

source: D. M. Rousseau, S. B. Sitkin, R. S. Burt, and C. Camerer. Not so different after all: A cross-discipline view of trust. In ACADEMY OF MANAGEMENT REVIEW, volume 23, pages 393–404, 1998).

psychology/micro-organizational behavior, strategy/economics:
"willingness to be vulnerable," proposed by Mayer, Davis, and Schoorman (1995).
"willingness to rely" on another (Doney, Cannon, & Mullen)
"confident, positive expectations" (Lewicki et al.)

"Trust is a psychological state comprising the intention to accept vulnerability based upon positive expectations of the intentions or behavior of an- other".

Trust is not a behavior (e.g., cooperation), or a choice (e.g., taking a risk), but an underlying psychological condition that can cause or result from such actions.
Trust is psychological and important to organizational life.

The conditions that must exist for trust to arise. Risk is one condition considered essential in psychological, sociological, and economic conceptualizations of trust (Coleman, 1990; Rotter, 1967; Williamson, 1993). The second necessary condition of trust is interdependence, where the interests of one party cannot be achieved without reliance upon an- other.

three phases of trust:
(1) building (where trust is formed or reformed),
(2) stability (where trust already exists),
(3) dissolution (where trust declines).
These phases of trust characterize the ebb and flow of relationships

depend on the function of trust, it can be seen as:
an independent variable (cause),
dependent variable (effect), or
interaction variable (a moderating condition for a causal relationship).

Trust can be affected by:
- reputation, particularly the historical trustworthiness of parties in previous interactions with others (Burt & Knez,1996)
- The social context (e.g., networks) that makes reputational effects possible.
- how individuals representing each firm relate to each other (Fichman & Goodman, 1996; Zaheer et al.)

In sum, what do we know about trust? We find that trust is a psychological state composed of the psychological experiences of individuals, dyads, and firms. There is a common underlying definition of trust across scholars from different disciplines, and this basic definition applies across trust's levels of analysis and develop- mental phases. Scholars tend to view trust dynamically but focus on specific phases in developing their conceptual frameworks. Some are interested in trust's beginning, others in its end, and still others in trust as an ongoing and stable phenomenon.

Monday, 28 March 2011

Old research Questions ..


Research Question1:
How to solve the problem of Trustworthiness of data in Business process management?
Investigative Questions:
a.     How to model Trustworthiness of data?
b.     How to build a trust annotated data?
c.     How to exploit Trust annotated data in BPM systems?
Research Question2:
How to solve the problem of Trustworthiness of Resources in Business process management?
Investigative Questions:
a.     How to model Trustworthiness of Resources?
b.     How to fill and update Trust informed resource profile?
c.     How to make use of these Trust profiles in BPM systems (e.g. Trust base work allocation)?
Research Question3:
How to strengthen the trust-aware systems by Mining Trust related information?
Investigative Questions:
a.     How to mine trust related information from typical log file?
b.     How to enrich log files with Trust related information?

Trust your process ..


If one can “Trust” data, and resources, then one can “Trust” the process, which means, in BPM to be able to say that this is a “Trusted” process, resources and data of this process should all be “Trusted”. 

Trust mining ..


Studying the BPM lifecycle showed that solving the problems of ‘data trustworthiness’ and ‘resource trustworthiness’ that would cover all stages of BPM lifecycle except for the ‘Diagnoses stage’ which why it is important to add a new question about the problem of ‘data mining of trust related information’. This could be concluded in the following question:
-       How to strengthen the trust-aware systems by Mining Trust related information?
This could be done at the beginning by mining any data related to trust as the first step, then as a second step that could be enhanced by designing the log files to be rich with Trust related information and that would help more in mining. So to answer the question ‘How to strengthen the trust-aware systems by Mining Trust related information?’ We have to answer the following Investigative Questions:
a.     How to mine trust related information from typical log file?
b.     How to enrich log files with Trust related information?

Trustworthiness for Resources & Data


An idea to deal with ‘resources trustworthiness’ is to have a “trust profile” related to each resource, the system should make use of available information to build these profiles that can be used to analyze the resource trustworthiness, which can be used in various ways (i.e. work allocation). To be able to use such idea it is important to know how to build these profiles, and how to make use of them. So, these are also important questions to answer to solve the problem of ‘Resource trustworthiness’:
a.     How to fill and update Trust informed resource profile?
b.     How to make use of these Trust profiles in BPM systems (e.g. Trust base work allocation)?
Similar idea could be used to solve the problem of ‘data trustworthiness’, as annotations could be added to data to represent trust requirements for the data (wither it is control data or object data), where a system could use these annotated data to honor the trust requirements. To apply such solution we first must answer the questions on how to annotate trust requirements within data, and how a BPM system can exploit these trust annotated data. So, another two important questions are:
a.     How to build a trust annotated data?
b.     How to exploit Trust annotated data in BPM systems?

Sunday, 27 March 2011

1st idea of data trustworthiness ..


Because data do not behave on there own (non-behavioral entity), so, to trust data in BPM will mean that data should resist any malicious attack and stay as they are expected to be. For example in a banking sector, if a transfer process was to ‘transfer $5,000 to account number 12345’ if the data got maliciously manipulated and the attacker changed the account number the process will end up not doing what it is expected to do. Another example if the attacker changed the data of ‘transfer to’ and made it ‘transfer from’ the client will end up loosing money instead of getting money. So it is important for both ‘control data’ and ‘object data’ to know if they are trustworthy r not, it is important for the resource and the system to know the trustworthiness of the data. There are few ideas on how to solve this problem, for example we can build trust-annotated data so system and resources will use these annotations to analyze the trustworthiness of the data.

control-flow trust, from a technical security point of view

Based on the definition of trust that we have established, to trust the control-flow means to make sure that the workflow will proceed as it suppose to and will resist being maliciously modified. That means firstly, to make sure that the design of the workflow was done according to the process owner’s needs and satisfy all requirements (which is related to process design). Secondly, to make sure that the system will correctly interpret the model and will not modify it. Thirdly, to make sure that the system will protect against any malicious modification of the workflow, which depends mostly on the system configuration and security settings. So first requirement is a real “Trust” requirement but it is related to ‘Process design’ which is out of the scope. The other requirement on the other hand is not a real requirement, because once a system is known to be trusted doing such task, there is no need to be tested every time, and most systems are used only after establishing that it is trustworthy and it would not modify the model. Third requirement is a real requirement that is related to process execution (process automation), for example if a bank is using an automated process, even if the executed model was according to requirements and it is working as it suppose to, there are no guarantee that the workflow will not be maliciously modified and the new workflow will send sensitive data to the public or allow untrusted resource to look in to classified data. That’s might raise a question: how to design control-flow in a way that resists any unauthorized modification?