期刊文献+

工作流系统中一个基于多权角色和规则的条件化RBAC安全访问控制模型 被引量:4

Conditioned secure access control model based on multi-weighted roles and rules in workflow system
下载PDF
导出
摘要 针对传统的RBAC模型不能表达复杂的工作流安全访问控制约束的缺点,提出了一个适合工作流系统的基于多权角色和规则的条件化安全访问控制模型CMWRRBSAC(conditioned multi-weighted role and rule based secure access control model)。该模型基于传统的RBAC模型,提出了基于动态角色分配的条件化RBAC方法,定义了基于多权角色的工作流系统访问授权新概念,并针对多个角色和多个用户协同激活任务的序约束问题,给出了基于令牌的序约束算法和基于加权角色综合的序约束算法,讨论了一个基于规则的职责分离约束建模方法,并给出了改进的规则一致性检验算法。 The traditional RBAC model cannot express complicated workflow secure access control constraint, so a new conditioned RBAC model suit for WfMS (workflow management system)-CMWRRBSAC (conditioned multi-weighted role and rule based secure access control model) was proposed on the basis of multi-weighted roles and rules. Based on the traditional RBAC model, a conditioned RBAC method was discussed on the basis of dynamic role assignment and a new concept of workflow access authorization was defined on the basis of multi-weighted roles. A sort algorithm based on token and a sort algorithm based on weighted roles synthesis were presented in allusion to the problem of multi-roles and multi-users sequence constraint in the process of executing tasks. A rule-based modeling method of separation of duties was discussed and its improved rule consistency check arithmetic was given.
出处 《通信学报》 EI CSCD 北大核心 2008年第2期8-16,共9页 Journal on Communications
基金 国家自然科学基金重大基金资助项目(60496321) 国家自然科学基金资助项目(60473003) 吉林省科技发展项目(20040526)~~
关键词 工作流 访问控制 职责分离 规则 多权角色 令牌 workflow access control separation of duties rule multi-weighted roles token
  • 相关文献

参考文献10

二级参考文献15

  • 1邓集波 洪帆.基于任务的授权模型.软件学报,2003,14(1):76~82.http://www.jos.org.cn/1000-9825/14/76.htm.,.
  • 2李慧芳 范玉顺.工作流系统时间管理.软件学报,2002.13(8):1552~1558.http://www.jos.org.cn/1000-9825/13/1552.pdf.,.
  • 3Fcrraiolo DF, Sandhu R, Guirila S, Kuhn DR, Chandramouli R. Proposed NIST standard for role-based access control. ACM Transactions on Information and System Security, 2001,4(3):224-274.
  • 4Botha RA, Eloff JHP. Access control in document centric workflow system: an agent-based approach. Computers & Security, 2001,20(6):525-532.
  • 5Wu SL, Sheth A, Miller J, Luo ZW. Authorization and access control of application data in workflow system. Journal of Intelligent Information System, 2002,18(1):71 -94.
  • 6Bertino E, Bonatti PA, Ferrari E. TRBAC: A temporal role-based access control model. ACM Transactions on Information and System Security, 2001,4(3): 191-223.
  • 7董光宇 卿斯汉 刘克龙.带时间特性的角色授权约束.软件学报,2002,13(8):1521~1527[EB/OL].http://www.jos.org.cn/1000-9825/13/1521.pdf.,.
  • 8邓集波 洪帆.基于任务的授权模型.软件学报,2003,14(1):76~82[EB/OL].http://www.jos.org.cn/1000-9825114/76.him.,.
  • 9李慧芳 范玉顺.工作流系统时间管理.软件学报,2002,13(8):1552-1558[EB/OL].http://wwwjos.org.cn/1000-9825/13/1552.pdf.,.
  • 10李慧芳 范玉顺.工作流系统时间管理.软件学报,2002,13(8):1552~1558.http://www.jos.org.cn/1000-9825/13/1552.pdf,.

共引文献289

同被引文献59

引证文献4

二级引证文献10

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部