
工作流系统中基于任务状态的转授权模型 被引量:4

Task-State-Based Delegation Model in Workflow System
摘要 为了解决工作流系统中多个用户协作完成某个任务时的权限分配问题,提出了工作流系统中用户-用户间基于任务状态的转授权模型,用任务处于某个状态的时间段作为转授权有效期的限制,将任务的部分权限作为转授权对象,在任务的各个状态下为不同的用户分配不同的权限。给出了模型的形式化定义,并提出了模型中转授权约束规则、冲突消解办法和转授权的撤销,最后举例说明该模型在实际工作流系统中的应用。模型能在不增加系统管理员负担的前提下,较好地解决工作流系统中多个用户协作完成某个任务时的授权问题。 To adapt to the situation that a task was executed by several users in cooperation,this paper proposed a user to user task-state-based delegation model in workflow system.It limited the delegation valid period in one state of the task,and took a part of task permissions as delegation object.It assigned different permissions to each users in cooperation in every state of the task.This paper posed the formal definition of the model,and proposed the delegation constraints and resolvment of delegation conflicts,as well as the revocation of delegaton.Finally an example was taken to show the practical application of the model.This model can solve the problem of permissions assignment well when several users cooperate to fullfil one task of a workflow,and won't increase the burdens of the administrator.
出处 《计算机技术与发展》 2011年第2期34-38,共5页 Computer Technology and Development
基金 教育部中央高校基本科研基金(CDJZR1017005)
关键词 工作流 任务状态 转授权 最小权限 workflow task state delegation least privileges
  • 相关文献



  • 1刘璟,周明天.基于SPKI证书的CORBA分布式授权服务[J].北京邮电大学学报,2003,26(z1):81-88. 被引量:1
  • 2廖旭,张力.工作流管理系统中一种基于任务的委托模式[J].计算机工程与应用,2005,41(7):44-46. 被引量:5
  • 3叶春晓,吴中福,符云清,钟将,冯永.基于属性的扩展委托模型[J].计算机研究与发展,2006,43(6):1050-1057. 被引量:17
  • 4翟征德.基于量化角色的可控委托模型[J].计算机学报,2006,29(8):1401-1407. 被引量:33
  • 5BARKA E, SANDHU R. Role-based delegation model/hierarchical roles(RBDM1)[C]//Proceedings of the 20th Annual Computer Security Applications Conference. Washington, D. C., USA: IEEE, 2004: 396-404. 被引量:1
  • 6ZHANG Longhua, AHN G J, CHU B T. A rule-based framework for role-based delegation[C]//Proceedings of the 6th ACM Symposium on Access Control Models and Technologies. New York, N. Y., USA:ACM, 2001:153-163. 被引量:1
  • 7BARKA E, SANDHU R. A role-based delegation model and some extensions[EB/OL]. [2008-11-10]. http://eprints. kfupm.edu. sa/20689/1/20689. pdf. 被引量:1
  • 8WAINER J, KUMAR A. A fine-grained, controllable, user-to- user delegation method in RBAC[C]//Proceedings of the 10th ACM Symposium on Access Control Models and Technologies. New York, N.Y., USA:ACM, 2005:59-66. 被引量:1
  • 9VENTER K, OLIVIER M S. The delegation authorization model: a model for the dynamic delegation of authorization rights in a secure workflow management system[EB/OL]. [2008-10-30]. http://icsa. cs. up. ac. za/issa/2002/proceedings/A02.pdf. 被引量:1
  • 10ATLURI V, BERTINO E, FERRARI E, et al. Supporting delegation in secure workflow management systems[C]//Proceedings the of 17th Annual IFIP WG 11.3 Conference on Data and Application of Security. New York, N. Y. , USA: ACM,2003 : 190-202. 被引量:1












使用帮助 返回顶部