首页> 外文期刊>Journal of computer security >Chinese wall security for decentralized workflow management systems
【24h】

Chinese wall security for decentralized workflow management systems

机译:分散式工作流管理系统的中国墙安全性

获取原文
获取原文并翻译 | 示例

摘要

Workflow systems are gaining importance as an infrastructure for automating inter-organizational interactions, such as those in Electronic Commerce. In such an environment, a centralized Workflow Management System is not desirable because: (ⅰ) it can be a performance bottleneck, and (ⅱ) the systems are inherently distributed, heterogeneous, and autonomous in nature. Decentralized execution of inter-organizational workflows may raise a number of security issues including those related to conflict-of-interest among competing organizations. In this paper, we first provide an approach to realize decentralized workflow execution, in which the workflow is divided into partitions, called self-describing workflows, and handled by a light weight workflow management component, called workflow stub, located at each organizational agent. Second, we identify the limitations of the traditional workflow model with respect to expressing the various types of join dependencies and extend the traditional workflow model suitably. Distinguishing the different types of dependencies among tasks is essential in the efficient execution of self-describing workflows. Finally, we recognize that placing the task execution agents that belong to the same conflict-of-interest class in one self-describing workflow may lead to unfair, and in some cases, undesirable results, akin to being on the wrong side of the Chinese wall. Therefore, to address the conflict-of-interest issues that arise in competitive business environments, we propose a decentralized workflow Chinese wall security model. We propose a restrictive partitioning solution to enforce the proposed model.
机译:工作流系统作为自动化组织间交互的基础结构正变得越来越重要,例如电子商务中的交互。在这样的环境中,集中式工作流管理系统是不理想的,因为:(ⅰ)它可能是性能瓶颈,并且(ⅱ)这些系统本质上是分布式的,异构的和自治的。组织间工作流的分散执行可能会引发许多安全问题,包括与竞争组织之间的利益冲突有关的问题。在本文中,我们首先提供一种实现分散式工作流执行的方法,该方法将工作流划分为多个分区(称为自描述工作流),并由位于每个组织代理处的轻量级工作流管理组件(称为工作流存根)进行处理。其次,我们确定了传统工作流程模型在表达各种类型的联接依赖方面的局限性,并适当地扩展了传统工作流程模型。区分任务之间的不同类型的依赖关系对于有效执行自描述工作流至关重要。最后,我们认识到,将属于同一利益冲突类的任务执行代理放在一个自我描述的工作流中可能会导致不公平的结果,在某些情况下会导致不良结果,就像在汉语的错误方面一样。壁。因此,为解决竞争性商业环境中出现的利益冲突问题,我们提出了一种分散式工作流中式墙安全模型。我们提出了一种限制性分区解决方案来实施提出的模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号