Satisfiability and Resiliency in Workflow Authorization Systems

被引:76
|
作者
Wang, Qihua [1 ]
Li, Ninghui [2 ]
机构
[1] IBM Corp, Almaden Res Ctr, San Jose, CA 95120 USA
[2] Purdue Univ, W Lafayette, IN 47907 USA
关键词
Security; Theory; Access control; fault tolerant; policy design;
D O I
10.1145/1880022.1880034
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We propose the role-and-relation-based access control (R(2)BAC) model for workflow authorization systems. In R(2)BAC, in addition to a user's role memberships, the user's relationships with other users help determine whether the user is allowed to perform a certain step in a workflow. For example, a constraint may require that two steps must not be performed by users who have conflicts of interests. We study computational complexity of the workflow satisfiability problem, which asks whether a set of users can complete a workflow. In particular, we apply tools from parameterized complexity theory to better understand the complexities of this problem. Furthermore, we reduce the workflow satisfiability problem to SAT and apply SAT solvers to address the problem. Experiments show that our algorithm can solve instances of reasonable size efficiently. Finally, it is sometimes not enough to ensure that a workflow can be completed in normal situations. We study the resiliency problem in workflow authorization systems, which asks whether a workflow can be completed even if a number of users may be absent. We formally define three levels of resiliency in workflow systems and study computational problems related to these notions of resiliency.
引用
收藏
页数:35
相关论文
共 50 条
  • [1] Satisfiability and resiliency in workflow systems
    Wang, Qihua
    Li, Ninghui
    COMPUTER SECURITY - ESORICS 2007, PROCEEDINGS, 2007, 4734 : 90 - +
  • [2] The bi-objective workflow satisfiability problem and workflow resiliency 1
    Crampton J.
    Gutin G.
    Karapetyan D.
    Watrigant R.
    Journal of Computer Security, 2017, 25 (01) : 83 - 115
  • [3] The Pandemic Impact on Organizations Security and Resiliency: The Workflow Satisfiability Problem
    Boughrous, Monsef
    El Bakkali, Hanan
    El Kandoussi, Asmaa
    HYBRID INTELLIGENT SYSTEMS, HIS 2021, 2022, 420 : 321 - 329
  • [4] Delegation and Satisfiability in Workflow Systems
    Crampton, Jason
    Khambhammettu, Hemanth
    SACMAT'08: PROCEEDINGS OF THE 13TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2008, : 31 - 40
  • [5] Architecture of Context-Aware Workflow Authorization Management Systems for Workflow-Based Systems
    Park, Seon-Ho
    Han, Young-Ju
    Eom, Jung-Ho
    Chung, Tai-Myoung
    MANAGEMENT ENABLING THE FUTURE INTERNET FOR CHANGING BUSINESS AND NEW COMPUTING SERVICES, PROCEEDINGS, 2009, 5787 : 375 - 384
  • [6] Conflict detection and resolution for authorization policies in workflow systems
    Chen-hua Ma
    Guo-dong Lu
    Jiong Qiu
    Journal of Zhejiang University-SCIENCE A, 2009, 10 : 1082 - 1092
  • [8] Conflict detection and resolution for authorization policies in workflow systems
    Ma, Chen-hua
    Lu, Guo-dong
    Qiu, Jiong
    JOURNAL OF ZHEJIANG UNIVERSITY-SCIENCE A, 2009, 10 (08): : 1082 - 1092
  • [9] Authorization and access control of application data in workflow systems
    Wu, SG
    Sheth, A
    Miller, J
    Luo, ZW
    JOURNAL OF INTELLIGENT INFORMATION SYSTEMS, 2002, 18 (01) : 71 - 94
  • [10] Authorization and Access Control of Application Data in Workflow Systems
    Shengli Wu
    Amit Sheth
    John Miller
    Zongwei Luo
    Journal of Intelligent Information Systems, 2002, 18 : 71 - 94