首页> 外文会议>IEEE International Conference on Services Computing >Modelling Workflow Executions under Role-Based Authorisation Control
【24h】

Modelling Workflow Executions under Role-Based Authorisation Control

机译:基于角色的授权控制下建模工作流程执行

获取原文

摘要

Workflows are often used to represent enterprise-type activities, and authorisation control is an important security consideration in enterprise-level applications. Role-Based Access Control (RBAC) is a popular authorisation control scheme under which users are assigned to certain roles, and the roles are associated with permissions. This paper presents a novel mechanism for modelling workflow execution in cluster-based resource pools under Role-Based Access Control (RBAC) schemes. Our modelling approach uses Coloured Timed Petri-Nets, and various authorisation constraints are modelled, including role constraints, temporal constraints, cardinality constraints, Binding of Duty and Separation of Duty constraints, etc. The interactions between workflow authorisation and workflow execution are also captured in the model. In this paper, the modelling mechanism is developed in such a fashion that the construction of the authorisation model for a workflow can be automated. This feature is very helpful in modelling a large collection of authorisation policies or complex workflows. A Petri-net simulation tool, the CPN-Tool, is utilised to implement the developed modelling mechanism and simulate the constructed model. Both system-level performance (e.g., utilisation of resource pools) and application-level performance (e.g., workflow response time) can be obtained from model simulations. This work can be used to plan system capacity and investigate the impact of authorization policies on system and application performance.
机译:工作流程通常用于表示企业型活动,授权控制是企业级应用程序中的重要安全性考虑因素。基于角色的访问控制(RBAC)是一个流行的授权控制方案,用户将分配给某些角色,并且角色与权限相关联。本文介绍了基于角色的访问控制(RBAC)方案的基于集群的资源池中的工作流程执行的新机制。我们的建模方法使用彩色定时培养网,并建模各种授权约束,包括角色限制,时间约束,基数限制,义务绑定以及占空比限制等。还捕获工作流授权和工作流程之间的交互。该模型。在本文中,以这种方式开发了建模机制,即可以自动构建工作流的授权模型的构建。此功能在建模大量授权策略或复杂工作流程方面非常有用。利用Petri-Net仿真工具,CPN工具,用于实现开发的建模机制并模拟构造的模型。可以从模型仿真中获得系统级性能(例如,资源池的利用率)和应用程序级性能(例如,工作流响应时间)。这项工作可用于规划系统能力,并调查授权政策对系统和应用程序性能的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号