【24h】

AW-RBAC: Access Control in Adaptive Workflow Systems

机译:AW-RBAC:自适应工作流系统中的访问控制

获取原文

摘要

Flexibility is one of the key challenges for Workflow Systems nowadays. Typically, a workflow covers the following four aspects which might all be subject to change: control flow, data flow, organizational structures, and application components (services). Existing work in research and practice shows that changes must be applied in a controlled manner in order to avoid security problems. In this context, attempts have been made to manage administrative or operative changes using role-based access control (RBAC) models. However, most approaches focus on either administrative changes such as role updating and administration or operative changes, for example, inserting a new activity into a running workflow instance. The distinct handling of certain changes is cumbersome and hence should be reduced by introducing a RBAC model that pays attention to all kinds of possible workflow changes. Hence, in this paper, we present an extended RBAC model for adaptive workflow systems (AW-RBAC) that includes change operations and a variety of objects that are subject to change within workflow systems. Under such a model supervised administrative and operative changes can be enforced on a set of objects in workflow systems. Doing so, the AW-RBAC model improves security during workflow changes and reduces administration costs. The AW-RBAC model is evaluated by means of practical examples and a proof-of-concept implementation.
机译:灵活性是当今工作流程系统的主要挑战之一。通常,工作流涵盖以下四个方面,所有这些方面都可能会发生变化:控制流,数据流,组织结构和应用程序组件(服务)。研究和实践中的现有工作表明,必须以受控方式应用更改,以避免安全问题。在这种情况下,已经尝试使用基于角色的访问控制(RBAC)模型来管理管理或操作上的更改。但是,大多数方法都侧重于管理更改(例如角色更新和管理)或操作更改,例如,将新活动插入正在运行的工作流实例中。某些更改的独特处理很麻烦,因此应通过引入关注所有可能的工作流更改的RBAC模型来减少这种更改。因此,在本文中,我们提出了适用于自适应工作流系统的扩展RBAC模型(AW-RBAC),其中包括变更操作和工作流系统中可能发生变更的各种对象。在这种模型下,可以对工作流系统中的一组对象实施监督的管理和操作更改。这样做,AW-RBAC模型提高了工作流程更改期间的安全性并降低了管理成本。 AW-RBAC模型是通过实际示例和概念验证实现进行评估的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号