摘要
针对现有基于任务-角色的访问控制模型中存在的角色继承和工作流责权和表达问题进行了研究,提出了面向协作的角色继承关系和任务组合原语,以适应分布式协作系统的需求。面向协作的角色继承根据系统中角色之间的管理关系将角色对任务的操作权分为三类,不同操作权代表了不同的职责。任务组合原语根据工作流基本形式和任务统一管理的需求,定义了组合任务和任务组合关系,给出了语言的文法描述,并结合面向协作的角色继承规范了角色定义组合任务的能力范围。实验结果表明,提出的两个方案提高了访问控制系统的安全性,灵活性和扩展性。
The existing problems of nowadays task-role-based access control models such as inheritance with role hierarchy, separation of duty and sequence expression in workflow are investigated. Then the collaboration-oriented inheritance with role hierarchy and task combining language are introduced to meet the requirements of distributed collaborative system. According to the supervising relationship between roles, collaboration-oriented inheritance with role hierarchy classifies the duty of users to task into three types, and assigns them to different users according to their responsibilities. According to basic forms of workflow and requirement of unified management to tasks, task combining language defines task combination and task combining relationship, corresponding grammar description and constraints are put forward. The proposed methods can enhance the security, flexibility and expansibility of access control mechanism in distributed collaborative systems as suggested in performance analysis.
出处
《计算机工程与设计》
CSCD
北大核心
2009年第11期2640-2644,2648,共6页
Computer Engineering and Design
基金
海军装备预研基金项目(4010601010201)
关键词
分布式协作系统
基于任务-角色的访问控制
职责分离
面向协作的角色继承
任务组合原语
distributed collaborative system
task-role-based access control
separation of duty
collaboration-oriented inheritance with role hierarchy
task combining language