摘要
在工作流中应用访问控制,数据在工作流中流动,执行操作的用户在改变,用户的权限也在改变,这与数据处理的上下文环境相关。采用传统的访问控制技术,如DAC,MAC,则难以做到这一点,若采用RBAC,也需要频繁地更换角色,且不适合工作流程的运转。文章在契约式的安全业务流程设计的基础上,利用泳道,建立基于泳道的安全工作流的访问控制模型。
In the workflow system, when the data flow, the users who execute the operation changes, the authority of the users changes too, both of them are related to the context of the data processing. Traditional access control technologies, such as DAC, MAC, are difficult to do this. In RBAC, roles must be changed frequently, which is not suitable to the workflow operation. So, we need a new access control model. Therefore, this paper will establish a secure workflow access control model based on lane and CSWF.
出处
《计算机与数字工程》
2009年第11期111-114,共4页
Computer & Digital Engineering