分析当前信息系统存在的主要问题,介绍信息交换平台是一个基于点对点(Peer to Peer)的信息发布系统。在这个系统里,从信息的产生、采集、加工、存储、发布、消费到监管,形成了一个完整的信息生命体系。基于XML技术,经过对信息交换平台...分析当前信息系统存在的主要问题,介绍信息交换平台是一个基于点对点(Peer to Peer)的信息发布系统。在这个系统里,从信息的产生、采集、加工、存储、发布、消费到监管,形成了一个完整的信息生命体系。基于XML技术,经过对信息交换平台的信息描述深入的研究,提出了开放信息模型(OIM),对信息进行统一的描述,使信息可以跨平台发布。OIM研究目标有两个:一个是信息模型的设计;另一个是信息模型在信息交换平台里的实现。本文重点设计了针对网络环境的用户授权管理模型、角色访问控制模型、工作流模型等,提供对应用系统的安全服务,从而避免应用系统和授权系统紧耦合,同时保证实现应用系统语言实现的无关性。提供了用户授权管理系统的运行界面,给出测试实例,比较了测试数据。实践证明,该研究使开放信息系统共享授权服务,加快开发速度,减少开发成本,使应用系统开发更易维护;另一方面,通过安全管理平台从全局的角度来保证系统完整性和一致性,减少敏感信息泄漏的机会。展开更多
In the context of workflow systems, security-relevant aspect is related to the assignment of activities to (human or automated) agents. This paper intends to cast light on the management of project-oriented workflow. ...In the context of workflow systems, security-relevant aspect is related to the assignment of activities to (human or automated) agents. This paper intends to cast light on the management of project-oriented workflow. A comprehensive authorization model is proposed from the perspective of project management. In this model, the concept of activity decomposition and team is introduced, which improves the security of conventional role-based access control. Furthermore, policy is provided to define the static and dynamic constraints such as Separation of Duty (SoD). Validity of constraints is proposed to provide a fine-grained assignment, which improves the performance of policy management. The model is applicable not only to project-oriented workflow applications but also to other teamwork environments such as virtual enterprise.展开更多
After analysis of the existing problems of traditional RBAC model, user group and resource domain are introduced to conduct finely granular extension of RBAC model. Extended model reduces the redundancy of roles, lowe...After analysis of the existing problems of traditional RBAC model, user group and resource domain are introduced to conduct finely granular extension of RBAC model. Extended model reduces the redundancy of roles, lowers the complexity of authorization management and enhances the flexibility and maintainability of users' authorization. It is well proved in its application in postgraduate student management system.展开更多
文摘分析当前信息系统存在的主要问题,介绍信息交换平台是一个基于点对点(Peer to Peer)的信息发布系统。在这个系统里,从信息的产生、采集、加工、存储、发布、消费到监管,形成了一个完整的信息生命体系。基于XML技术,经过对信息交换平台的信息描述深入的研究,提出了开放信息模型(OIM),对信息进行统一的描述,使信息可以跨平台发布。OIM研究目标有两个:一个是信息模型的设计;另一个是信息模型在信息交换平台里的实现。本文重点设计了针对网络环境的用户授权管理模型、角色访问控制模型、工作流模型等,提供对应用系统的安全服务,从而避免应用系统和授权系统紧耦合,同时保证实现应用系统语言实现的无关性。提供了用户授权管理系统的运行界面,给出测试实例,比较了测试数据。实践证明,该研究使开放信息系统共享授权服务,加快开发速度,减少开发成本,使应用系统开发更易维护;另一方面,通过安全管理平台从全局的角度来保证系统完整性和一致性,减少敏感信息泄漏的机会。
文摘In the context of workflow systems, security-relevant aspect is related to the assignment of activities to (human or automated) agents. This paper intends to cast light on the management of project-oriented workflow. A comprehensive authorization model is proposed from the perspective of project management. In this model, the concept of activity decomposition and team is introduced, which improves the security of conventional role-based access control. Furthermore, policy is provided to define the static and dynamic constraints such as Separation of Duty (SoD). Validity of constraints is proposed to provide a fine-grained assignment, which improves the performance of policy management. The model is applicable not only to project-oriented workflow applications but also to other teamwork environments such as virtual enterprise.
文摘After analysis of the existing problems of traditional RBAC model, user group and resource domain are introduced to conduct finely granular extension of RBAC model. Extended model reduces the redundancy of roles, lowers the complexity of authorization management and enhances the flexibility and maintainability of users' authorization. It is well proved in its application in postgraduate student management system.