高级检索

    面向服务的工作流访问控制模型研究

    A Service-Oriented Workflow Access Control Model

    • 摘要: 随着企业全球化、企业业务联合与分化的发展,企业组织结构更加动态化,企业业务流程经常发生变更,这都增加了工作流访问控制的复杂性.针对此问题,从工作流访问控制模型与流程模型分离的角度,提出一种面向服务的工作流访问控制模型——SOWAC模型.服务是流程任务的抽象执行和实施访问控制的基本单元,用服务的访问控制替代流程任务的访问控制.说明了SOWAC模型的组成元素及实施实例,提出一种基于服务授权历史的动态责任分离约束方法,并给出SOWAC模型在工作流系统中的实际应用.

       

      Abstract: With the progress of enterprise globalization and the development of combination and differentiation in enterprise business, organizations become more dynamic, and business processes are frequently changing. As a result, workflow access control turns more complicated. To solve this problem, in view of decoupling the workflow access control model from the process model, a service-oriented workflow access control (SOWAC) model is presented. In the SOWAC model, service is the abstraction of a task and the unit for applying access control. Therefore, access control of tasks is replaced with access control on services. The elements of the SOWAC model are described and the enforcement of SOWAC is illustrated by an example workflow. Then the dynamic separation of duty for the SOWAC model is proposed based on the authorization history of services. By applying the SOWAC model in a real workflow system, it shows that the SOWAC model is practical and effectual.

       

    /

    返回文章
    返回