A flexible access control model for dynamic workflow using extended WAM and RBAC

2Citations
Citations of this article
7Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Security issues pertaining to workflow systems are becoming increasingly important for the cross-enterprises interoperability in insecure environments. Among them, access control for information confidentiality and integrity has attracted widespread attention. However, in the context of the contemporary dynamic business environment, the traditional workflow authorization model (WAM) faces limitations in handling the consequences of dynamic workflow changes and exceptions, since it focuses primarily on the synchronization of authorization flow by using authorization templates (ATs). In this paper, we propose a flexible access control with dynamic checking features for handling workflow changes and exceptions. Extended temporal role-based access control and flexible workflow authorization template are adopted in order to further enhance the traditional AT, thereby ensuring information confidentiality and integrity. Additionally, a case study applying the proposed model to uEngine, an open source workflow management system, is presented. © 2008 Springer Berlin Heidelberg.

Cite

CITATION STYLE

APA

Yang, L., & Choi, Y. (2008). A flexible access control model for dynamic workflow using extended WAM and RBAC. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 5236 LNCS, pp. 488–497). https://doi.org/10.1007/978-3-540-92719-8_44

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free