DocumentCode :
3741784
Title :
Towards an attribute-based authorization model with task-role-based access control for WfMS
Author :
Kui Liu; Zhurong Zhou; Qianguo Chen; Xiaoli Yang
Author_Institution :
Southwest University, Chongqing 400715, China
fYear :
2015
Firstpage :
361
Lastpage :
371
Abstract :
Over the years, a majority of organizations and enterprises have been successfully performing various workflow management systems (WfMS) to manage their daily workflow. Security still is one of the key challenges for WfMS nowadays. Researchers proposed various secure authorization models for WfMS which mainly focus on the pre-authorization dealing with the outside unauthorized access. However, workflow is dynamic, in which the attributes of subjects or objects could be changed during or after the access process. The situation may lead to the changes of users´ access clearances, which may give rise to the insiders´ threats only through the pre-authorization without further checking. This paper proposes an attribute-based authorization model with task-role-based access control for WfMS that includes the ongoing-authorization (onA) and the pre-authorization (preA).In this model, special administrative access is performed by preA. The normal users´ access is dynamically authorized by onA, and the authorization is closely related to attributes of subjects and objects, separating the access from tasks, roles and users indirectly. According to the authorization mechanism, the model can assign access permissions to users dynamically, then decrease the insiders´ threats throughout the duration of accessing. We evaluated the model by a practical example and a proof-of-concept demonstration.
Keywords :
"Adaptation models","Context modeling","Banking","Legged locomotion","Context","Authorization"
Publisher :
ieee
Conference_Titel :
Communication Technology (ICCT), 2015 IEEE 16th International Conference on
Print_ISBN :
978-1-4673-7004-2
Type :
conf
DOI :
10.1109/ICCT.2015.7399859
Filename :
7399859
Link To Document :
بازگشت