DocumentCode :
2283114
Title :
A dynamic workflow authorization method based on participant expression rules
Author :
Tang, Da ; Guo, Jing ; Zhang, Qi
Author_Institution :
Dept. of Comput. Sci. & Technol., Dalian Univ. of Technol., Dalian, China
Volume :
4
fYear :
2011
fDate :
10-12 June 2011
Firstpage :
345
Lastpage :
349
Abstract :
The execution of workflow processes requires authorizations for enforcing the assignment of tasks to participants according to the security, functionality and management policies of an organization. A role-based authorization model is commonly adopted in most workflow systems and has become a research topic in the area of workflow. However, the existing role-based access control models cannot assign tasks to right participants according to the context in workflow activities. Therefore, this method lacks flexible and dynamic allotment capability and cannot meet the requirements of complex business processes during the runtime of workflow instances. In this paper a dynamic workflow authorization method based on participants´ expression rules is proposed. In the period of process modeling, this method, which applies some expression rules into the participant of each activity, can resolve the problem of dynamic authorization of the tasks during the runtime of workflow instances. The method also supports the least privilege policies and the policies of separation of duties, and achieves the definition of complex business processes, meanwhile enhances the flexibility of workflow participant definition. At last, the demonstration of reimbursement application process is also presented to testify the practicability and strong expression ability.
Keywords :
authorisation; business data processing; workflow management software; complex business processes; dynamic workflow authorization method; functionality policies; management policies; participant expression rules; reimbursement application process; security policies; task assignment; workflow processes; workflow systems; Authorization; Engines; Organizations; Runtime; Workflow management software; dynamic authorization; least privilege; participant expression; separation of duties; workflow;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Science and Automation Engineering (CSAE), 2011 IEEE International Conference on
Conference_Location :
Shanghai
Print_ISBN :
978-1-4244-8727-1
Type :
conf
DOI :
10.1109/CSAE.2011.5952865
Filename :
5952865
Link To Document :
بازگشت