首页> 外文OA文献 >Business Process Access Control (BPAC): workflow-based authorisation for complex systems
【2h】

Business Process Access Control (BPAC): workflow-based authorisation for complex systems

机译:业务流程访问控制(BpaC):基于工作流的复杂系统授权

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Segregation of duties and least privilege are two business principles that protect an organisation’s valuable data from information leak. In this thesis we demonstrate how these business principles can be addressed through workflow-based access control. We present Business Process Access Control (BPAC), a workflow-based access control modelling environment that properly enacts the key business principles through constraints and we implement BPAC in the applied pi calculus. We ensure that constraints are correctly applied within our BPAC implementation by introducing the concept of stores. We propose a selection of security properties in respect of the business principles and we develop tests for these properties. The collusion metric is introduced as a simple indicator as to the resistance of a workflow-based access control policy to fraudulent collusion. We identify an anonymity property for workflows as the inability of an outside observer to correctly match agents to workflow tasks and we propose that anonymity provides protection against collusion. We introduce a lightweight version of labelled bisimilarity: the abstraction test and we apply this test to workflow security properties. We develop a test for anonymity using labelled bisimilarity and we demonstrate its application through simple examples.
机译:职责分离和特权最小化是两项业务原则,可以保护组织的宝贵数据免遭信息泄露。在本文中,我们演示了如何通过基于工作流的访问控制来解决这些业务原则。我们提出了业务流程访问控制(BPAC),这是一种基于工作流的访问控制建模环境,可通过约束适当地制定关键业务原则,并在应用的演算中实现BPAC。通过引入商店的概念,我们确保在BPAC实施中正确应用约束。我们建议根据业务原则选择安全属性,并针对这些属性进行测试。引入共谋度量作为关于基于工作流的访问控制策略对欺诈性共谋的抵抗力的简单指标。我们将工作流的匿名性标识为外部观察者无法正确地将代理与工作流任务匹配,并且我们建议匿名性提供防止共谋的保护。我们引入了标记为双相似性的轻量级版本:抽象测试,并将此测试应用于工作流安全性属性。我们使用标记的双相似性开发了一个匿名性测试,并通过简单的示例演示了其应用。

著录项

  • 作者

    Newton Derrick;

  • 作者单位
  • 年度 2012
  • 总页数
  • 原文格式 PDF
  • 正文语种 {"code":"en","name":"English","id":9}
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号