【24h】

Cooperative Role-Based Administration

机译:基于合作的角色管理

获取原文

摘要

In large organizations the administration of access privileges (such as the assignment of an access right to a user in a particular role) is handled cooperatively through distributed administrators in various different capacities. A quorum may be necessary, or a veto may be possible for such a decision. In this paper we present two major contributions: We develop a Role-Based Access Control (RBAC) approach for specifying distributed administration requirements, and procedures between administrators, or administration teams, extending earlier work on distributed (modular) authorization. While a comprehensive specification in such a language is conceivable it would be quite tedious to evaluate, or analyze, their operational aspects and properties in practice. For this reason we create a new class of extended Petri Nets called Administration Nets such that any RBAC specification of (cooperative) administration requirements (given in terms of predicate logic formulas) can be embedded into an Administration Net. This net behaves within the constraints specified by the logical formulas, and at the same time, it explicitly exhibits all needed operational details such as to allow for an efficient and comprehensive formal analysis of administrative behavior. We introduce the new concepts and illustrate their use in several examples. While Administration Nets are much more refined and (behaviorally) explicit than work flow systems our work provides for a constructive step towards novel work-flow management tools as well.
机译:在大型组织中,访问权限管理(例如在特定角色中的访问权限的访问权限)通过各种不同容量的分布式管理员协同处理。可能需要仲裁,或者可以对这种决定进行否决权。在本文中,我们提出了两项​​主要贡献:我们开发了一种基于角色的访问控制(RBAC)方法,用于指定分布式管理要求,管理员或管理团队之间的程序,延伸前期分布式(模块化)授权。虽然可以想到这种语言的全面规范,但在实践中评估或分析他们的运作方面和性质是非常繁琐的。出于这个原因,我们创建了一个名为管理网的新阶级扩展Petri网,以便任何RBAC规范(合作)给药要求(根据谓词逻辑公式给出)可以嵌入到管理网中。此净行为在逻辑公式指定的约束中,同时,它明确地展示了所有所需的运营细节,以便允许对行政行为的有效和全面的正式分析。我们介绍了新的概念,并说明了他们在几个例子中的使用。虽然管理网络更加精致和(行为)明确而不是工作流程系统,我们的工作也为新颖的工作流管理工具提供了建设性的步骤。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号