【24h】

A New Role-Based Authorization Model in a Corporate Workflow Systems

机译:企业工作流系统中基于角色的新授权模型

获取原文
获取原文并翻译 | 示例

摘要

The Role Based Access Control (RBAC) model contains a structural representation of the enterprise organization, facilities for the administration of access control, and is extremely flexible. The traditional RBAC model can be applied to WorkFlow Management System (WFMS) well, but applying it causes some issues. Since the senior roles inherit all the permissions of the junior roles and all the permissions are accumulated for the top senior role, applying the traditional RBAC to WFMS does not meet the access control requirements: least privilege principle, Separation of Duty (SoD). This can cause problems with the misuse of rights and the opportunity to commit fraud. It can make it difficult to guarantee the integrity of the system. In order to solve these problems, we propose applying Restricted Permission Inheritance RBAC, called RPI-RBAC, to WFMS authorization. We evaluate the advantages and benefits of applying the RPI-RBAC model to WFMS authorization in design time and runtime.
机译:基于角色的访问控制(RBAC)模型包含企业组织的结构表示形式,用于访问控制管理的设施,并且非常灵活。传统的RBAC模型可以很好地应用于WorkFlow管理系统(WFMS),但是应用它会引起一些问题。由于高级角色继承了初级角色的所有权限,并且所有权限都是顶级高级角色的累积,因此将传统的RBAC应用于WFMS不能满足访问控制要求:最小特权原则,职责分离(SoD)。这会导致权利滥用和欺诈的机会。这可能会难以保证系统的完整性。为了解决这些问题,我们建议对WFMS授权应用称为RPI-RBAC的受限权限继承RBAC。我们评估了在设计时和运行时将RPI-RBAC模型应用于WFMS授权的优点和好处。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号