期刊文献+

基于角色的适应性工作流系统访问控制模型 被引量:2

ROLE-BASED ACCESS CONTROL MODEL FOR ADAPTIVE WORKFLOW SYSTEMS
下载PDF
导出
摘要 现有的一些工作流系统访问控制模型局限于活动执行权限控制,难以满足适应性工作流系统的访问控制需求。针对适应性工作流系统的权限控制需求,对适应性工作流系统的操作行为进行分析和总结,确定操作对象、用户、操作方法为研究对象,对监控和业务过程变更进行细粒度划分,给出了规范化的形式化描述。在此基础上提出基于角色的访问控制的授权模型以及与系统的集成,描述角色、用户和对象等要素之间关系,给出授权方法,保证操作的合理性,有效解决适应性工作流系统中安全控制问题,满足了不同层次人员对监控权限的灵活需求。 Some existing access control model for workflow systems are limited to tasks execution. It is difficult to satisfy the security requirement for adaptive workflow systems. To solve the problem, operation behaviors of adaptive workflow management systems are analyzed and summarized. Object, user and operation are considered as the main elements for research. Formal description and fine granularity partition about these elements are given. Finally,based on the above work,a role-based access control model and integration with systems are proposed, and relationships among role, user and operation are described. In addition, authorization method is given to guarantee operation security and rationality. The problem of security is solved effectively, and the users' flexible requirements for permission are satisfied.
出处 《计算机应用与软件》 CSCD 2009年第2期53-54,79,共3页 Computer Applications and Software
基金 国家十一五科技支撑计划项目(2006BAF01A46) 上海市科技发展基金重大项目(04DZ11007) 赣教技字(2007)208号
关键词 适应性工作流系统 访问控制 权限 角色 Adaptive workilow system Access control Privilege Role
  • 相关文献

参考文献7

  • 1Sadiq S. Workflows in dynamic environments? Can they be managed [ C ]. Proceedings of the Second International Symposium on Cooperative Database Systems for Advanced Applications, Woollongong, Australia, 1999:27 -28. 被引量:1
  • 2Joeris G. Defining flexible workflow execution behaviors [ C ]. Proceed- ings of Enterprise-wide and cross-enterprise workflow managementconcepts, systems, applications, Ulm, Germany : Ulmer Informatik Beriohte, 1999:49 - 55. 被引量:1
  • 3Rinderle S. Schema Evolution in Process Management Systems[ D]. University of Ulm ,2004. 被引量:1
  • 4Wainer J,Bartheimess P,Kumar A. W-RBAC-a workflow security model incorporating controlled overriding of constraints[ J ]. International Journal of Cooperative Information Systems,2003,12 (4) :455 - 486. 被引量:1
  • 5马亮,顾明.基于角色的工作流系统访问控制模型[J].小型微型计算机系统,2006,27(1):136-140. 被引量:14
  • 6Sandhu R,Ferraiolo D,Kuhn R. The NIST model for role-based access control: Towards a unified standard: Proceedings of the Fifth ACM Workshop on Role Based Access Control [ C ]. Berlin, Germany : ACM, 2000:47 -63. 被引量:1
  • 7Workflow Management Coalition Workflow Standard. Workfiow Process Definition Interfaee-XML Process Definition Language[ EB/OL]. [ October 25,2002 ] http ://www. wfrae, org/standards/docs, htm. 被引量:1

二级参考文献13

  • 1Workflow Management Coalition. The workflow reference model[Z]. Document Number TC-00-1003. Issue 1. 1. 19 Jan 1995. 被引量:1
  • 2Workflow Management Coalition. Workflow security considerations-white paper[Z]. Document Number WFMC-TC-IO19. Issue 1.0. Feb 1998. 被引量:1
  • 3Snyder L. Formal models of capability-based protection systems[J]. IEEE Transactions on Computers, 1981,30 (3) ; 172-181. 被引量:1
  • 4Ferraiolo D, Kuhn R. 1992. Role-based access control[C]. in Proceedings of the NIST-NSA National (USA) Computer Security Conference, 554-563. 被引量:1
  • 5Ferraiolo D F, Sandhu R et al. Proposed NIST standard forrole-based access control[J]. ACM Transactions on Information and System Security, 2001.4(3):224-274. 被引量:1
  • 6Thomas R K, Sandhu R S. Conceptual foundations for a model of task-based authorizations [C]. Computer Security Foundations Workshop VII, 1994. CSFW 7. Proceedings , 14-16 Jun 1994, 66-79. 被引量:1
  • 7Thomas R K, Sandhu R S. Task-based authorization controls(TBAC) : A family of models for active and enterprise-oriented authorization management[C]. Proceedings of the IF1P WG11.3 Workshop on Database Security, 1997:166-181. 被引量:1
  • 8Bertino E, Ferrari E, Atluri V. The specification and enforcement of authorization constraints in workflow management systems[J]. ACM Transactions on Information and System Security, 1999,2(1):65-104. 被引量:1
  • 9Reinhardt A Botha, Jan H P Eloff. Separation of duties for access control enforcement in workflow environments [J]. IBM Systems Journal, 2001,40(3) : 666-682. 被引量:1
  • 10Kumar A. A framework for handling delegation in workflow management systems[C]. Proceedings of Workshop on Information, Charlotte, NC, 1999. 被引量:1

共引文献13

同被引文献10

引证文献2

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部