An Access Control Model for Task-Oriented Workflow

Yong-he WEI,Chen-gen WANG,Qi-lin SHU,Ming-xu MA
DOI: https://doi.org/10.3321/j.issn:1005-3026.2008.03.022
2008-01-01
Abstract:Analyzing what are required for the access control of workflow, an access control model for task-oriented workflow is put forward, in which the idea of authorized task in order to separate the relation between roles and permissions. An authorization task is introduced to make the executive roles in no relation to authority, where the authority least approved to execute a task and the role assigned to execute the task are both the attributes of task authorization. The model also defines the conflict relationship between different tasks, then gives the dynamic constraint rules on the authorization to ensure and enforce the implementation of security strategies. In this model, the authorization flow is synchronized with workflow so as to meet the access control s requirements of dynamic authorization, authority least approved and separation of responsibility from duty. Differing from existing models, in the proposed model the separation of authority from executive role cancels the coupling of organizational model with workflow model.
What problem does this paper attempt to address?