• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2005, Vol. 27 ›› Issue (11): 3-5.

• 论文 • 上一篇    下一篇

基于TBAC的分布式工作流访问控制模型研究

沈显君 李俊峰 庄超 魏开平   

  • 出版日期:2005-11-01 发布日期:2010-06-24

  • Online:2005-11-01 Published:2010-06-24

摘要:

基于分布式的工作流系统面临着日益复杂的数据资源安全管理难题,基于TBAC的访问控制可以与工作事务处理流程紧密结合,因此可根据工作流中任务和任务状态实现对数据 资源的动态访问控制。本文在分析基于任务的访问控制原理基础之上,将基于角色的授权机制与基于任务的访问控制相结合,采用任务层次分解方法建立全局工作流图,应用
用分散管理策略建立分布式工作流的安全访问控制模型,并对该模型实现进行了详细阐述。

关键词: 基于任务的访问控制 分布式工作流 任务层次分解

Abstract:

One of the most challenging problems in large distributed workflow management systems is the complexity of security administration. The TBAC (task-ba sed access control) shows powerful capability in dynamic access control by being integrated with workflow transaction processing, and manages the permi  issions dynamically according to the tasks and the task status of workflow. This paper integrates the role-based authorization with the task-based acces s control by analyzing the principle of task-based access control, and a task level partitioning method is introduced to present the global workflow schema. In addition, decentralization management policies are applied to establish the access control of distributed workflow, and the realization of this model is expatiated as well.

Key words: (task-based access control, distributed workflow, task level partitioning)