计算机工程与应用 ›› 2011, Vol. 47 ›› Issue (2): 91-94.DOI: 10.3778/j.issn.1002-8331.2011.02.029

• 网络、通信、安全 • 上一篇    下一篇

面向工作流应用的可组合授权模型

吴 荣   

  1. 华侨大学 数学科学学院,福建 泉州 362021
  • 收稿日期:2009-01-06 修回日期:2009-03-17 出版日期:2011-01-11 发布日期:2011-01-11
  • 通讯作者: 吴 荣

Composited authorization model for workflow applications

WU Rong   

  1. School of Mathematical Science,Huaqiao University,Quanzhou,Fujian 362021,China
  • Received:2009-01-06 Revised:2009-03-17 Online:2011-01-11 Published:2011-01-11
  • Contact: WU Rong

摘要: 针对分布式工作流系统授权管理的动态性、统一性和自治性的特点,将RBAC的授权管理思想和TBAC的动态访问机制结合起来,提出了支持工作流组合和动态授权控制的可组合授权模型。该模型提供了从工作流的组成结构和执行关系进行建模的方法,通过将各个处理单元的授权方案按照工作流的组合结构、执行依赖关系和主体依赖关系进行组合,从而构造适应更复杂的工作流系统的授权方案。对模型的定义和组合运算进行了形式化描述,给出了模型的表达能力和一致性、组合运算的兼容性和安全性的相关性质分析。最后介绍了支持动态授权的授权控制引擎原型。

Abstract: Aiming at challenges of dynamic,united and autonomic in authorization management for distributed workflow system,a composited authorization model for workflow application systems is proposed,which combines authorization ideology of RBAC and dynamic access control mechanism of TBAC.The model provides methods of modelling on composition structures and execution relations in a workflow system,thus a corresponding authorization policy can be constructed by composing authorization policies of processing-units,according to composition structures,execution dependences and subject dependences in the workflow system.Formal descriptions of model definitions and composition calculus are presented.Expressive power and consistency of model,compatibility of composition calculus and their security properties are analyzed in detail.Furthermore,the prototype of an authorization control engine for dynamic permission control is introduced.

中图分类号: