完整後設資料紀錄
DC 欄位語言
dc.contributor.author吳美玉en_US
dc.contributor.authorMei-Yu Wuen_US
dc.contributor.author劉敦仁en_US
dc.contributor.authorDuen-Ren Liuen_US
dc.date.accessioned2014-12-12T02:29:57Z-
dc.date.available2014-12-12T02:29:57Z-
dc.date.issued2004en_US
dc.identifier.urihttp://140.113.39.130/cdrfb3/record/nctu/#GT008834801en_US
dc.identifier.urihttp://hdl.handle.net/11536/69889-
dc.description.abstractRole-based authorizations for assigning tasks of workflows to roles/users are crucial to security management in workflow management systems. The authorizations must enforce Separation of Duty (SoD) constraints to prevent fraud and errors. This work analyzes and defines several duty-conflict relationships among tasks, and designs authorization rules to enforce SoD constraints based on the analysis. A novel authorization model that incorporates authorization rules is then proposed to support the planning of assigning tasks to roles/users, and the run-time activation of tasks. Different from existing work, the proposed authorization model considers the AND/XOR split structures of workflows and execution dependency among tasks to enforce separation of duties in assigning tasks to roles/users. Moreover, this work discusses the authorization management of organizational roles in a process-view. A process-view, an abstracted process derived from a base process, can provide adaptable task granularity to suit different needs of workflows participants. Authorization mechanisms are proposed to derive a role’s permissions on virtual activities based on the role’s permissions on base activities. The proposed authorization mechanisms consider duty-conflict relationships among base activities to enforce SoD. A prototype system is developed to realize the effectiveness of the proposed authorization model.zh_TW
dc.description.abstractRole-based authorizations for assigning tasks of workflows to roles/users are crucial to security management in workflow management systems. The authorizations must enforce Separation of Duty (SoD) constraints to prevent fraud and errors. This work analyzes and defines several duty-conflict relationships among tasks, and designs authorization rules to enforce SoD constraints based on the analysis. A novel authorization model that incorporates authorization rules is then proposed to support the planning of assigning tasks to roles/users, and the run-time activation of tasks. Different from existing work, the proposed authorization model considers the AND/XOR split structures of workflows and execution dependency among tasks to enforce separation of duties in assigning tasks to roles/users. Moreover, this work discusses the authorization management of organizational roles in a process-view. A process-view, an abstracted process derived from a base process, can provide adaptable task granularity to suit different needs of workflows participants. Authorization mechanisms are proposed to derive a role’s permissions on virtual activities based on the role’s permissions on base activities. The proposed authorization mechanisms consider duty-conflict relationships among base activities to enforce SoD. A prototype system is developed to realize the effectiveness of the proposed authorization model.en_US
dc.language.isoen_USen_US
dc.subject以角色為基礎的存取控制zh_TW
dc.subject工作流程zh_TW
dc.subject流程觀zh_TW
dc.subject授權管理zh_TW
dc.subject權責區分zh_TW
dc.subjectrole-based access controlen_US
dc.subjectworkflowen_US
dc.subjectprocess-viewen_US
dc.subjectauthorization managementen_US
dc.subjectseparation of dutyen_US
dc.title以角色與工作為基礎的工作流程授權管理zh_TW
dc.titleRole and Task Based Authorization Management for Workflowsen_US
dc.typeThesisen_US
dc.contributor.department資訊管理研究所zh_TW
顯示於類別:畢業論文


文件中的檔案:

  1. 480101.pdf

若為 zip 檔案,請下載檔案解壓縮後,用瀏覽器開啟資料夾中的 index.html 瀏覽全文。