The Delegation Authorization Model: A Model For The Dynamic Delegation Of Authorization Rights In A Secure Workflow Management System
نویسنده
چکیده
A workflow is a coordinated arrangement of related tasks in an automated process, the systematic execution of which, ultimately achieves some goal. Tasks that comprise the workflow process are typically dependent on one another. Security, in a workflow context, involves the implementation of access control security mechanisms to ensure that task dependencies are coordinated and that tasks are performed by authorized subjects only. A Workflow Authorization Model (WAM) [AH96b] has already been developed to enforce security principles on workflows, by addressing the granting and revoking of authorizations in a Workflow Management System (WFMS). This WAM satisfies most criteria required for an optimal access control model for workflows, some of which cannot be met through pure role-based access control (RBAC) mechanisms. This paper addresses the delegation of task authorizations within a workflow process by subjects in the organizational structure. The proposed The Delegation Authorization Model (DAM) will work within the security constraints imposed by the WAM when deciding whether delegations will be approved or denied. It will also take into account the dynamically determined constraints imposed by the DAM
منابع مشابه
Authorization models for secure information sharing: a survey and research agenda
This article presents a survey of authorization models and considers their 'fitness-for-purpose' in facilitating information sharing. Network-supported information sharing is an important technical capability that underpins collaboration in support of dynamic and unpredictable activities such as emergency response, national security, infrastructure protection, supply chain integration and emerg...
متن کاملAccess control in ultra-large-scale systems using a data-centric middleware
The primary characteristic of an Ultra-Large-Scale (ULS) system is ultra-large size on any related dimension. A ULS system is generally considered as a system-of-systems with heterogeneous nodes and autonomous domains. As the size of a system-of-systems grows, and interoperability demand between sub-systems is increased, achieving more scalable and dynamic access control system becomes an im...
متن کاملRB-GDM: A Role-Based Grid Delegation Model
Grid delegation is the procedure by which a valid user endows another user or a program or service with the ability to act on that user’s behalf. Delegation is the primary form of authorization in grids. The large and geographically distributed, dynamic, heterogeneous and scalable grid environment poses unique delegation requirements. Presently there are no standard mechanisms to guide grid del...
متن کاملWorkflow-based Authorization Service in Grid
In a distributed environment, specific rights may be required while a task is controlled and processed. A user should delegate enough rights to a task for processing. Tasks cannot work correctly if delegated rights are insufficient, or security threats may occur if delegated rights are excessive. Restricted delegation is the step that delegates proper rights to a task, and that enables finegrai...
متن کاملDelegatable Authorization Program and Its Application
Data protection is a significant issue in any secure information systems. In this paper, we present a decentrailzed authorization delegation model in which users can be delegated, granted or forbidden some access rights. This security model is formulated as an extended logic program, and the detailed considerations of how to evaluate the semantics of the program is given. In particular, the con...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2002