DocumentCode
2374441
Title
Capability-Role-Based Delegation in Workflow Systems
Author
Hasebe, Koji ; Mabuchi, Mitsuhiro
Author_Institution
Grad. Sch. of Syst. & Inf. Eng., Univ. of Tsukuba, Tsukuba, Japan
fYear
2010
fDate
11-13 Dec. 2010
Firstpage
711
Lastpage
717
Abstract
Various security models for supporting delegation in workflow systems have been proposed to achieve flexible access control in collaborative business processes. Since workflow systems come into their own when controlling large-scale business processes in a well-structured organization, these models are often based on role-based access control (RBAC). However, to realize a higher level of collaboration enabling users in different organizations to complete a common workflow, it is necessary to support cross-domain delegation of tasks. For this purpose, we propose a delegation model for workflow systems that extends the capability-role-based access control (CRBAC) model introduced in our previous work. The central idea behind our proposed model is that authority to perform tasks, as well as roles, are mapped to capabilities, thereby realizing delegation by capability transfer. By adopting the approach of a capability-based access control mechanism, our model provides both flexibility and reduced administration costs, thus allowing it to cope with unexpected changes in task assignments. We demonstrate these advantages by considering an example.
Keywords
authorisation; capability based access control; capability role based access control model; capability role based delegation; capability transfer; collaborative business process; cross-domain delegation; large-scale business process; role-based access control; security models; task assignment; well-structured organization; workflow systems; RBAC; capability-based access control; delegation; workflow systems;
fLanguage
English
Publisher
ieee
Conference_Titel
Embedded and Ubiquitous Computing (EUC), 2010 IEEE/IFIP 8th International Conference on
Conference_Location
Hong Kong
Print_ISBN
978-1-4244-9719-5
Electronic_ISBN
978-0-7695-4322-2
Type
conf
DOI
10.1109/EUC.2010.112
Filename
5703599
Link To Document