针对现有的访问控制模型应用于工作流系统时的不足,提出了一个面向工作流的柔性策略访问控制模型.该模型通过引入授权许可的概念,定义了各任务执行期间各角色可被授予的权限及相应的情景约束,实现了工作流中的动态访问控制和灵活的授权策略定义.为了描述工作流系统中的复杂授权规则,模型扩展了一种与授权许可相关的约束,并提供了有效的授权约束冲突检测与消解方法.分析表明模型具有良好的安全性与实用性,能较好地满足工作流系统对访问控制的需求.
Access control models proposed so far cannot satisfy the access requirements in workflow systems very well. To address the issue, a flexible policy access control model for workflows was proposed. By the introduction of authorization certificate, which defines the authorization that can be performed during task execution and the constraints should be satisfied, dynamic access control in workflows is realized and the flexible definition of authorization policies is supported. For the description of complicated authori- zation rules, authorization certificate related constraints were defined. Furthermore, efficient conflict detection and resolution rules for authorization constraints were also provided. Analysis shows that the model has good security and practicability. It can meet the requirements for access control in workflow systems adequately.