Types for task-based access control in workflow systems

被引:5
|
作者
Lu, Y. [1 ]
Zhang, L. [2 ]
Sun, J. [2 ]
机构
[1] Shenzhen Univ, Coll Software, Shenzhen 518060, Peoples R China
[2] Tsinghua Univ, Sch Software, Key Lab Informat Secur, Minist Educ, Beijing 100084, Peoples R China
基金
中国国家自然科学基金;
关键词
D O I
10.1049/iet-sen:20070098
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Task-based access control (TBAC) is a flexible security mechanism, which has been widely implemented in workflow management systems. In TBAC, permissions are assigned to tasks and users can only obtain the permissions during the execution of tasks. The authors aim at developing a method for formalising and analysing security properties of workflow systems under TBAC policy. To achieve this goal, the authors first present WFPI, workflow pi-calculus. By adding task execution and submission primitives, and tagging each agent with its executing and distributing tasks, WFPI can flexibly represent the concepts and elements in workflow systems. Then, based on WFPI, a type system is proposed to ensure that the well-typed workflow systems can abide by the TBAC policy at run time, by avoiding run-time access violations. To the best of one's knowledge, the present research is the first attempt to study workflow access control by process calculus and types.
引用
收藏
页码:461 / 473
页数:13
相关论文
共 50 条
  • [1] Task Delegation Based Access Control Models for Workflow Systems
    Gaaloul, Khaled
    Charoy, Francois
    SOFTWARE SERVICES FOR E-BUSINESS AND E-SOCIETY, 2009, 305 : 400 - +
  • [2] The consistency of task-based authorization constraints in workflow systems
    Tan, KJ
    Crampton, J
    Gunter, CA
    17TH IEEE COMPUTER SECURITY FOUNDATIONS WORKSHOP, PROCEEDINGS, 2004, : 155 - 169
  • [3] Task-based access control for virtual organizations
    Periorellis, P
    Parastatidis, S
    SCIENTIFIC ENGINEERING OF DISTRIBUTED JAVA APPLICATIONS, 2005, 3409 : 38 - 47
  • [4] Task-based access control model and its implementation
    Hong, Fan
    Zhao, Xiaofei
    Huazhong Keji Daxue Xuebao (Ziran Kexue Ban)/Journal of Huazhong University of Science and Technology (Natural Science Edition), 2002, 30 (01):
  • [5] Role and task-based access control in the PerDis groupware platform
    Univ of London, United Kingdom
    Proc ACM Workshop Role Based Access Control, (115-121):
  • [6] Role-based authorizations for workflow systems in support of task-based separation of duty
    Liu, DR
    Wu, MY
    Lee, ST
    JOURNAL OF SYSTEMS AND SOFTWARE, 2004, 73 (03) : 375 - 387
  • [7] Research on Task-Based Usage Control Core Models in Workflow for Manufacturing Environment
    Xu, Xiao Lin
    ADVANCED RESEARCH ON MATERIAL SCIENCE, ENVIROMENT SCIENCE AND COMPUTER SCIENCE III, 2014, 886 : 378 - 381
  • [8] An Organization and Task Based Access Control Model for Workflow System
    Wang, Baoyi
    Zhang, Shaomin
    ADVANCES IN WEB AND NETWORK TECHNOLOGIES, AND INFORMATION MANAGEMENT, PROCEEDINGS, 2007, 4537 : 485 - 490
  • [9] Task-Based Entailment Constraints for Basic Workflow Patterns
    Wolter, Christian
    Schaad, Andreas
    Meinel, Christoph
    SACMAT'08: PROCEEDINGS OF THE 13TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2008, : 51 - 60
  • [10] Role and task-based access control model for web service integration
    Yu, D. (zjydg@163.com), 2012, Binary Information Press, P.O. Box 162, Bethel, CT 06801-0162, United States (08):