王伟然, 张洵, 范玉顺. 业务过程管理中基于组织和角色语义的访问控制[J]. 信息与控制, 2009, 38(3): 276-280.
引用本文: 王伟然, 张洵, 范玉顺. 业务过程管理中基于组织和角色语义的访问控制[J]. 信息与控制, 2009, 38(3): 276-280.
WANG Wei-ran, ZHANG Xun, FAN Yu-shun. Organization and Role Semantic Based Access Control of Rusiness Process Management[J]. INFORMATION AND CONTROL, 2009, 38(3): 276-280.
Citation: WANG Wei-ran, ZHANG Xun, FAN Yu-shun. Organization and Role Semantic Based Access Control of Rusiness Process Management[J]. INFORMATION AND CONTROL, 2009, 38(3): 276-280.

业务过程管理中基于组织和角色语义的访问控制

Organization and Role Semantic Based Access Control of Rusiness Process Management

  • 摘要: 针对现有业务过程访问控制方法不能充分满足业务过程管理(BPM)实际需求的问题,首先分析了基于角色的访问控制(RBAC)和基于任务的访问控制(TBAC)等方法的不足;然后提出了一种基于组织结构和角色语义的访问控制(OR-SBAC)模型和方法,并采用形式化方法描述了OR-SBAC模型及其部件;最后给出了OR-SBAC的应用案例.OR-SBAC进一步划分了角色和受控主体,使用企业的组织结构进行用户与角色间的关联,在角色授权过程中通过角色适配器,基于一阶谓词逻辑进行角色语义推理,并考虑了时间和空间上下文等问题.OR-SBAC方法的描述能力强,权限分配效率高,能够满足业务过程管理中访问控制的复杂性、多样性和灵活性等方面的需求.

     

    Abstract: Current access control methods of business process can not meet the practical requirements of business process management(BPM).In order to solve this problem,disadvantages of the access control methods including role-based access control(RBAC) and task-based access control(TBAC) are analyzed.Then,an organization and role semantic based access control(OR-SBAC) model and method are proposed,its model along with the formal description of its components is presented,and an application example is given.The OR-SBAC method provides further classification of the roles and the controlled subjects,utilizes organizational structure to describe the relationship between user and role,fulfills authorization through role adapter by illation based on role semantics,and considers contexts of time and space.The strong description ability and high authorization efficiency of the OR-SBAC method meets the requirements of complexity,variety and flexibility in BPM.

     

/

返回文章
返回