在分析虚拟企业访问控制的基本要求以及现有访问控制模型特点的基础上,提出一种基于项目团队和任务角色的高效动态访问控制模型。该模型在无缝集成底层企业级基于角色访问控制模型的基础上,在上层根据任务流程将各盟员企业划分为不同的项目团队,进而实现了基于项目团队和任务角色的分层细粒度动态访问控制。同时,通过定义用户权限更新及撤销算法并引入自动角色指派策略和自动授权策略,实现了虚拟企业工作流系统的动态权限管理,支持虚拟企业中用户—角色和角色—任务—权限的自动指派。
Based on analyzing the special requirements of information access control in Virtual Enterprises (VE) and the characteristics of the existing access control models, a high effective dynamic access control model based on Project-Team (PT) and Task-Role (TR) named PT-TR Based Access Control (PT-TRBAC) was proposed. On the premise of seamless integrating the enterprise-level RBAC model, the proposed access control model divided virtual enterprise members into different project teams according to the task flow, by which hierarchical fine-grained project-team-based dynamic access control on public information was realized. Meanwhile, the algorithms to update and revoke user's authorities, the automatic role assignment policy and the automatic authorization policy were further given. By these methods, the workflow system could be dynamically managed, and the roles of users could be auto- matically assigned and authorized in VE.