• DocumentCode
    2374441
  • Title

    Capability-Role-Based Delegation in Workflow Systems

  • Author

    Hasebe, Koji ; Mabuchi, Mitsuhiro

  • Author_Institution
    Grad. Sch. of Syst. & Inf. Eng., Univ. of Tsukuba, Tsukuba, Japan
  • fYear
    2010
  • fDate
    11-13 Dec. 2010
  • Firstpage
    711
  • Lastpage
    717
  • Abstract
    Various security models for supporting delegation in workflow systems have been proposed to achieve flexible access control in collaborative business processes. Since workflow systems come into their own when controlling large-scale business processes in a well-structured organization, these models are often based on role-based access control (RBAC). However, to realize a higher level of collaboration enabling users in different organizations to complete a common workflow, it is necessary to support cross-domain delegation of tasks. For this purpose, we propose a delegation model for workflow systems that extends the capability-role-based access control (CRBAC) model introduced in our previous work. The central idea behind our proposed model is that authority to perform tasks, as well as roles, are mapped to capabilities, thereby realizing delegation by capability transfer. By adopting the approach of a capability-based access control mechanism, our model provides both flexibility and reduced administration costs, thus allowing it to cope with unexpected changes in task assignments. We demonstrate these advantages by considering an example.
  • Keywords
    authorisation; capability based access control; capability role based access control model; capability role based delegation; capability transfer; collaborative business process; cross-domain delegation; large-scale business process; role-based access control; security models; task assignment; well-structured organization; workflow systems; RBAC; capability-based access control; delegation; workflow systems;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Embedded and Ubiquitous Computing (EUC), 2010 IEEE/IFIP 8th International Conference on
  • Conference_Location
    Hong Kong
  • Print_ISBN
    978-1-4244-9719-5
  • Electronic_ISBN
    978-0-7695-4322-2
  • Type

    conf

  • DOI
    10.1109/EUC.2010.112
  • Filename
    5703599