摘要
现有的一些工作流系统访问控制模型局限于活动执行权限控制,难以满足适应性工作流系统的访问控制需求。针对适应性工作流系统的权限控制需求,对适应性工作流系统的操作行为进行分析和总结,确定操作对象、用户、操作方法为研究对象,对监控和业务过程变更进行细粒度划分,给出了规范化的形式化描述。在此基础上提出基于角色的访问控制的授权模型以及与系统的集成,描述角色、用户和对象等要素之间关系,给出授权方法,保证操作的合理性,有效解决适应性工作流系统中安全控制问题,满足了不同层次人员对监控权限的灵活需求。
Some existing access control model for workflow systems are limited to tasks execution. It is difficult to satisfy the security requirement for adaptive workflow systems. To solve the problem, operation behaviors of adaptive workflow management systems are analyzed and summarized. Object, user and operation are considered as the main elements for research. Formal description and fine granularity partition about these elements are given. Finally,based on the above work,a role-based access control model and integration with systems are proposed, and relationships among role, user and operation are described. In addition, authorization method is given to guarantee operation security and rationality. The problem of security is solved effectively, and the users' flexible requirements for permission are satisfied.
出处
《计算机应用与软件》
CSCD
2009年第2期53-54,79,共3页
Computer Applications and Software
基金
国家十一五科技支撑计划项目(2006BAF01A46)
上海市科技发展基金重大项目(04DZ11007)
赣教技字(2007)208号