节点文献

基于工作流任务状态的访问控制模型及其应用研究

Research on the Task Status-based Access Control Model of Workflow and Its Application

【作者】 黄俊华

【导师】 陈传波;

【作者基本信息】 华中科技大学 , 计算机应用技术, 2006, 硕士

【摘要】 工作流(Workflow)技术通过运用计算机自动执行组织机构中的部分或全部业务流程,从而显著提高业务流程处理的性能和效率。在商业、保险、银行、行政管理等领域中,通过互联网得到越来越广泛的应用。与此同时,对系统的安全性的要求也变得越来越重要。针对基于传统的访问控制模型中,自主访问控制(DAC)模型资源管理分散,强制访问控制(MAC)模型不能实现完整性访问控制;而基于角色的访问控制(RBAC)模型不能实现授权动态分配,以及基于任务的访问控制(TBAC)模型中授权管理过于复杂等缺点,提出了一种基于任务状态的访问控制模型(TSBAC)。基于任务状态的权限分配模型中引入了角色,同时以任务状态为基础,用二维矩阵描述了角色与任务、任务与状态、状态与权限之间的关系,并将各种关系转换成对应的关系数据库表,然后利用关系数据库中表的连接运算,计算了在任意给定时刻角色、任务和权限之间的关系,从而更简单,清晰的反应出了角色、任务、权限之间的关系。这种模型实现了对角色权限的动态分配,提高了数据访问安全性。Web下基于任务状态的访问控制技术结合了Web服务等技术的优点和基于任务状态访问控制技术的安全特性,所以在Web应用上有很好的应用前景。Rhombus跨国销售管理信息系统中的安全控制系统采用的是一个基于任务状态的访问控制的系统。根据客户的需求,设计合理的访问控制系统结构,并慎重的考虑访问控制系统和业务系统之间的关系。合理的选择访问控制的粒度是该项目成功的关键。

【Abstract】 Workflow is a technology to use the computer to process whole or part of application automatically in organization system and lead to significant increases in processing performance and efficiency. Using internet technology it has been applied in business, assurance, bank and administration management. At the same time, more and more attentions are paid to system security.In the traditional access control models, Discretionary Access Control (DAC) is too dispersive in resource management, Mandatory Access Control (MAC) is short of integrality control; Role-based Access Control (RBAC) can’t authorize privilege dynamically, and in Task-based Access Control (TBAC) the authorization is too complex, therefore, a Task Status-based Access (TSBAC) model is presented.In TSBAC, the role is used and based on the status of the task, the relationship between the roles and tasks, the tasks and status, and the status and privilege are all depicted with the two-dimensional matrix, then use the tables of database to depict these relationships and using joint operation to calculate the relationship of the role, task and privilege, it’s more easily and clearly to depict the relationship of the role, task and privilege. This model can dynamically distribute the privilege and improve the security of the data access.Task Status-based Access Control in web environment combines the merit of web system and the security of Task Status-based Access Control. So it has wide future in web application.The Security system of the Rhombus sale management information system is a Task Status-based Access Control system. Base the requirement of the client to design a rational framework of the access control system. And the relationship between access control system and business application system should also be thought over. To select the suitable access control granularity is the key to design the security system.

【关键词】 Web服务访问控制任务状态角色
【Key words】 Web serviceAccess controlTask statusRole
  • 【分类号】TP393.08
  • 【被引频次】6
  • 【下载频次】216
节点文献中: 

本文链接的文献网络图示:

本文的引文网络