摘要
在研究工作流已有安全策略的基础上,提出了基于工作流任务实例变迁的动态访问控制模型,通过角色执行工作流任务实例,并结合工作流任务上下文内容确定任务实例所处的不同状态,动态地将任务权限传递给执行角色,用户通过角色分配自动拥有执行角色的访问权限,实现了对工作流的动态安全访问。同时,对模型的动态访问控制机制进行了形式化描述,并结合电力系统工作流给出了具体的动态访问控制设计。
By studying the existing security strategies in a workflow, a dynamic access control model based on the task instances migration in workflow is presented. The model provides a dynamic access control mechanism that depends on the interaction among the multi-roles, tasks and permission in the workflow. The task gets the authorized permission and then the roles execute the task instances workflow in the context and get the corresponding authorized task instances permission when the workflow is running in different status. The users also obtain the permission that the roles owned. So, the dynamic access control in the workflow is realized. Finally, a formal description of the dynamic access control mechanism and the detailed design scheme of the dynamic access control in the workflow for electronic power information systems are given.
出处
《电力系统自动化》
EI
CSCD
北大核心
2005年第13期56-59,63,共5页
Automation of Electric Power Systems
关键词
工作流
多角色
任务实例变迁
动态访问控制
安全
Management information systems
Mathematical models
Scheduling
Security systems