DocumentCode
3741784
Title
Towards an attribute-based authorization model with task-role-based access control for WfMS
Author
Kui Liu; Zhurong Zhou; Qianguo Chen; Xiaoli Yang
Author_Institution
Southwest University, Chongqing 400715, China
fYear
2015
Firstpage
361
Lastpage
371
Abstract
Over the years, a majority of organizations and enterprises have been successfully performing various workflow management systems (WfMS) to manage their daily workflow. Security still is one of the key challenges for WfMS nowadays. Researchers proposed various secure authorization models for WfMS which mainly focus on the pre-authorization dealing with the outside unauthorized access. However, workflow is dynamic, in which the attributes of subjects or objects could be changed during or after the access process. The situation may lead to the changes of users´ access clearances, which may give rise to the insiders´ threats only through the pre-authorization without further checking. This paper proposes an attribute-based authorization model with task-role-based access control for WfMS that includes the ongoing-authorization (onA) and the pre-authorization (preA).In this model, special administrative access is performed by preA. The normal users´ access is dynamically authorized by onA, and the authorization is closely related to attributes of subjects and objects, separating the access from tasks, roles and users indirectly. According to the authorization mechanism, the model can assign access permissions to users dynamically, then decrease the insiders´ threats throughout the duration of accessing. We evaluated the model by a practical example and a proof-of-concept demonstration.
Keywords
"Adaptation models","Context modeling","Banking","Legged locomotion","Context","Authorization"
Publisher
ieee
Conference_Titel
Communication Technology (ICCT), 2015 IEEE 16th International Conference on
Print_ISBN
978-1-4673-7004-2
Type
conf
DOI
10.1109/ICCT.2015.7399859
Filename
7399859
Link To Document