首页> 外文期刊>Information Systems >DW-RBAC: A formal security model of delegation and revocation in workflow systems
【24h】

DW-RBAC: A formal security model of delegation and revocation in workflow systems

机译:DW-RBAC:工作流系统中委派和吊销的正式安全模型

获取原文
获取原文并翻译 | 示例
       

摘要

One reason workflow systems have been criticized as being inflexible is that they lack support for delegation. This paper shows how delegation can be introduced in a workflow system by extending the role-based access control (RBAC) model. The current RBAC model is a security mechanism to implement access control in organizations by allowing users to be assigned to roles and privileges to be associated with the roles. Thus, users can perform tasks based on the privileges possessed by their own role or roles they inherit by virtue of their organizational position. However, there is no easy way to handle delegations within this model. This paper tries to treat the issues surrounding delegation in workflow systems in a comprehensive way. We show how delegations can be incorporated into the RBAC model in a simple and straightforward manner. The new extended model is called RBAC with delegation in a workflow context (DW-RBAC). It allows for delegations to be specified from a user to another user, and later revoked when the delegation is no longer required. The implications of such specifications and their subsequent revocations are examined. Several formal definitions for assertion, acceptance, execution and revocation are provided, and proofs are given for the important properties of our delegation framework.
机译:工作流系统被批评为缺乏灵活性的原因之一是它们缺乏对委派的支持。本文展示了如何通过扩展基于角色的访问控制(RBAC)模型在工作流系统中引入委派。当前的RBAC模型是一种安全机制,用于通过允许将用户分配给角色以及将特权与角色相关联来在组织中实施访问控制。因此,用户可以根据自己的角色或凭借其组织位置继承的角色所拥有的特权来执行任务。但是,没有简单的方法来处理此模型中的委托。本文试图全面解决工作流系统中的委派问题。我们展示了如何以简单明了的方式将委托纳入RBAC模型。新的扩展模型称为RBAC,在工作流上下文中具有委派(DW-RBAC)。它允许将委派从一个用户指定给另一个用户,然后在不再需要委派时撤销。研究了此类规范及其后续撤销的含义。提供了一些断言,接受,执行和吊销的正式定义,并为我们的委托框架的重要属性提供了证明。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号