首页> 外文会议>Australasian conference on information security and privacy >BP-XACML an Authorisation Policy Language for Business Processes
【24h】

BP-XACML an Authorisation Policy Language for Business Processes

机译:BP-XACML一种业务流程的授权策略语言

获取原文

摘要

XACML has become the defacto standard for enterprise-wide, policy-based access control. It is a structured, extensible language that can express and enforce complex access control policies. There have been several efforts to extend XACML to support specific authorisation models, such as the OASIS RBAC profile to support Role Based Access Control. A number of proposals for authorisation models that support business processes and workflow systems have also appeared in the literature. However, there is no published work describing an extension to allow XACML to be used as a policy language with these models. This paper analyses the specific requirements of a policy language to express and enforce business process authorisation policies. It then introduces BP-XACML, a new profile that extends the RBAC profile for XACML so it can support business process authorisation policies. In particular, BP-XACML supports the notion of tasks, and constraints at the level of a task instance, which are important requirements in enforcing business process authorisation policies.
机译:XACML已成为企业范围内基于策略的访问控制的事实上的标准。它是一种结构化,可扩展的语言,可以表达和执行复杂的访问控制策略。已经进行了一些努力来扩展XACML以支持特定的授权模型,例如OASIS RBAC配置文件以支持基于角色的访问控制。有关支持业务流程和工作流系统的授权模型的许多建议也已出现在文献中。但是,尚无任何公开的工作描述扩展以允许XACML用作这些模型的策略语言。本文分析了表达和执行业务流程授权策略的策略语言的特定要求。然后,它引入了BP-XACML,这是一个新的配置文件,它扩展了XACML的RBAC配置文件,因此它可以支持业务流程授权策略。特别是,BP-XACML支持任务的概念以及任务实例级别的约束,这是在执行业务流程授权策略时的重要要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号