首页 | 本学科首页   官方微博 | 高级检索  
     

基于情景约束的工作流柔性访问控制模型
引用本文:马晨华,王进,裘炅,陆国栋. 基于情景约束的工作流柔性访问控制模型[J]. 浙江大学学报(工学版), 2010, 44(12): 2297-2308. DOI: 10.3785/j.issn.1008-973X.2010.12.011
作者姓名:马晨华  王进  裘炅  陆国栋
作者单位:1.浙江大学 工程与计算机图形学研究所,浙江 杭州 310027; 2.杭州电子科技大学 计算机学院,浙江 杭州 310018
基金项目:浙江省重大科技专项社会发展资助项目(2008C13073, 2009C03015-1).
摘    要:针对现有的访问控制模型在工作流系统中,基于情景的动态授权和灵活的任务相关授权等问题,提出一个应用于工作流系统的基于情景约束的柔性访问控制模型.模型定义了基于情景约束的角色指派策略和角色授权策略,分析了策略间的关系,对策略间可能存在的冲突进行了分类,给出策略冲突的静态和动态检测规则,并提出优先级规则和冲突消解策略的概念,安全管理员可以根据系统需求灵活地确定冲突消解的方式;模型还给出基于最小角色指派策略集和最小角色授权策略集的角色分配与授权决策算法,实现了工作流系统中基于情景的动态授权,并支持用户-角色和角色-权限的自动指派.

关 键 词:工作流  角色指派策略  角色授权策略  冲突检测与消解

Flexible context-constraint-based access control model for workflows
MA Chen-hua,WANG Jing,QIU Jiong,LU Guo-dong. Flexible context-constraint-based access control model for workflows[J]. Journal of Zhejiang University(Engineering Science), 2010, 44(12): 2297-2308. DOI: 10.3785/j.issn.1008-973X.2010.12.011
Authors:MA Chen-hua  WANG Jing  QIU Jiong  LU Guo-dong
Affiliation:1. Engineering and Computer Graphics Institute, Zhejiang University, Hangzhou 310027, China;2. College of Computer, Hangzhou Danzi University, Hangzhou 310018,China
Abstract:Access control models proposed so far provide no support for context-based dynamic authorization and flexible authorization policy definition for tasks. To address these issues, a flexible context-constraint-based access control model was proposed for workfolws. The concepts of context-constraint-based role assignment policy and context constraint based role authorization policy were defined. The interrelationships between policies were analyzed and the conflicts exhibited by policies were classified. Static and dynamic conflict detection methods were provided to maintain the consistency of policies. By the introduction of two new concepts, priority rule and conflict resolution policy, a flexible approach to resolve conflicts were provide. The security administrator can choose the method of resolving conflicts flexibly according to system requirements by defining priority rules and conflict resolution policies. Furthermore, the role assignment algorithm and the authorization decision algorithm based on the minimum sets of role assignment policies and role authorization policies were given. The model provides support for context-based dynamic authorization, automatic user-role and role-permission assignment.
Keywords:workflow  role assignment policy  role authorization policy  conflict detection and resolution
本文献已被 CNKI 等数据库收录!
点击此处可从《浙江大学学报(工学版)》浏览原始摘要信息
点击此处可从《浙江大学学报(工学版)》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号