针对现有访问控制模型在工作流系统应用中存在的局限,构建了一种改进的基于任务一角色的访问控制模型.该模型结合基于角色的访问控制(RBAC)和基于任务的访问控制(TBAC)模型的优点,按现实需求分别对角色和任务进行分类,在保证系统安全性的同时降低了访问策略的复杂性.以远程稿件处理系统为例,讨论了该模型在实际应用中的有效性.
Existing access control models cannot satisfy all the characteristics in the application of workflow systems. To address this issue, an improved access control model based on task-role is put forward. The new model which classifies roles and tasks according to practical requirements, integrates the strong points of role-based access control model (RBAC) and task-based access control model (TBAC). It is specified that the proposed model lowers the complexity of access strategy and ensures the security as well. A remote paper disposal system is described to illustrate the validity of the model.