摘要
以工作流信息模型安全机制不足为研究对象,通过模型扩展的方法,建立一种安全工作流访问控制模型ETRBAC。该模型在典型T-RBAC模型基础上,提出了职责分离约束和基数约束等问题的解决方案。结合优秀开源工作流管理系统Shark,设计并实现了ETRBAC模型中的相关安全机制,形成S-Shark(secure-Shark)工作流管理系统。S-Shark具有安全性、易用性和可扩展性等优势。
Considering the poor security mechanism in workflow management system, and with the method of improving work- flow information model, this paper presented a security workflow access control model. Based on the traditional model T- RBAC, the new model resolved the separation of duty constraint and cardinality constraint. Finally the paper implemented a secure workflow management system S-Shark(secure-Shark). S-Shark system was designed based on Java open source project Shark system, in which ETRBAC model' s secure mechanisms come to truth. The S-Shark system provides high security, convenient and high expansibility.
出处
《计算机应用研究》
CSCD
北大核心
2009年第4期1515-1516,1519,共3页
Application Research of Computers
基金
国家教育部科学研究重点资助项目(107106)
2008年度陕西师范大学青年科技资助项目(200801021)
关键词
工作流
工作流管理系统
访问控制
授权
约束
workflow
workflow management
access control
authorization
constraint