在面向服务的工作流访问控制模型中,角色的任务授权随着系统任务状态的变化而变化,一个任务往往有多个不同的角色指派方案。为了确定最优方案,在面向服务的角色访问控制模型基础上,引入了风险的概念,提出了形式化描述风险的方法。通过对不同角色执行任务风险的评估来确定执行角色,使工作流系统具有更好的安全性,同时通过角色风险权值的动态变化有效地平衡了角色间的负载,可以有效提高系统的效率。
Role assignment change dynamically with the change of state of the task in service-oriented workflow system. There are many role assignment schemes for the implementation of a task. In order to select better scheme, based on the serviceoriented role-based access control model in workflow system, introduced the concept of risk, and then proposed methods of describing risks. Through comparing the risks of implementing a task by different roles, system can select better access control assignment. And It can also balance the task load among roles with the change of risk weight of roles. The schemes can enhance the system security and flexibility.