標題: Role-based authorizations for workflow systems in support of task-based separation of duty
作者: Liu, DR
Wu, MY
Lee, ST
資訊管理與財務金融系 註:原資管所+財金所
Department of Information Management and Finance
關鍵字: workflow system;separation of duty;role-based access control;authorization management
公開日期: 1-十一月-2004
摘要: Role-based authorizations for assigning tasks of workflows to roles/users are crucial to security management in workflow management systems. The authorizations must enforce separation of duty (SoD) constraints to prevent fraud and errors. This work analyzes and defines several duty-conflict relationships among tasks, and designs authorization rules to enforce SoD constraints based on the analysis. A novel authorization model that incorporates authorization rules is then proposed to support the planning of assigning tasks to roles/users, and the run-time activation of tasks. Different from existing work, the proposed authorization model considers the AND/XOR split structures of workflows and execution dependency among tasks to enforce separation of duties in assigning tasks to roles/users. A prototype system is developed to realize the effectiveness of the proposed authorization model. (C) 2003 Elsevier Inc. All rights reserved.
URI: http://dx.doi.org/10.1016/S0164-1212(03)00175-4
http://hdl.handle.net/11536/25663
ISSN: 0164-1212
DOI: 10.1016/S0164-1212(03)00175-4
期刊: JOURNAL OF SYSTEMS AND SOFTWARE
Volume: 73
Issue: 3
起始頁: 375
結束頁: 387
顯示於類別:期刊論文


文件中的檔案:

  1. 000224158900002.pdf

若為 zip 檔案,請下載檔案解壓縮後,用瀏覽器開啟資料夾中的 index.html 瀏覽全文。