【24h】

Research on A Dynamic Workflow Access Control Model

机译:动态工作流访问控制模型的研究

获取原文
获取原文并翻译 | 示例

摘要

In recent years, the access control technology has been researched widely in workflow system, two typical technologies of that are RBAC (Role-Based Access Control) and TBAC (Task-Based Access Control) model, which has been successfully used in the role authorizing and assigning in a certain extent. However, during the process of complicating a system's structure, these two types of technology can not be used in minimizing privileges and separating duties, and they are inapplicable when users have a request of frequently changing on the workflow's process. In order to avoid having these weakness during the applying, a variable flow dynamic role_task_view (briefly as DRTVBAC) of fine-grained access control model is constructed on the basis existed model. During the process of this model applying, an algorithm is constructed to solve users' requirements of application and security needs on fine-grained principle of privileges minimum and principle of dynamic separation of duties. The DRTVBAC model is implemented in the actual system, the figure shows that the task associated with the dynamic management of role and the role assignment is more flexible on authority and recovery, it can be met the principle of least privilege on the role implement of a specific task permission activated; separated the authority from the process of the duties completing in the workflow; prevented sensitive information discovering from concise and dynamic view interface; satisfied with the requirement of the variable task-flow frequently.
机译:近年来,访问控制技术已经在工作流系统中得到了广泛的研究,其中的两种典型技术是基于角色的访问控制(RBAC)和基于任务的访问控制(TBAC)模型,已成功地用于角色授权中。并在一定程度上分配。但是,在使系统结构复杂化的过程中,无法使用这两种技术来最小化特权和分离职责,并且当用户要求频繁更改工作流程时,它们不适用。为了避免在应用过程中存在这些缺点,在现有模型的基础上构造了一种细粒度访问控制模型的可变流动态role_task_view(简称DRTVBAC)。在该模型应用过程中,构造了一种算法,以最小的特权最小原则和动态职责分离原则来满足用户的应用需求和安全需求。 DRTVBAC模型是在实际系统中实现的,从图中可以看出,与角色动态管理相关的任务和角色分配在授权和恢复方面更加灵活,可以满足对角色实现的最小特权原则。特定任务权限已激活;将权限与工作流中完成的职责过程分开;防止通过简洁,动态的视图界面发现敏感信息;经常满足可变任务流的需求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号