• 论文 •    

工作流系统中的委托授权机制研究

魏永合,王成恩,马明旭   

  1. 1.东北大学 机械工程与自动化学院,辽宁沈阳110004;2.沈阳理工大学 机械工程学院,辽宁沈阳110168;3.东北大学 教育部流程工业综合自动化重点实验室,辽宁沈阳110004
  • 出版日期:2009-01-15 发布日期:2009-01-25

Delegation authorization mechanism for workflow system

WEI Yong-he, WANG Cheng-en, MA Ming-xu   

  1. 1.School of Mechanical Engineering & Automation, Northeastern University, Shenyang 110004, China;2.School of Mechanical Engineering, Shenyang Ligong University, Shenyang 110168, China;3.Ministry of Education Key Lab for Process Industry Automation, Northeastern University, Shenyang 110004, China
  • Online:2009-01-15 Published:2009-01-25

摘要: 目前对工作流系统中委托授权的研究都是在已有的授权模型基础上添加适用于此模型的委托和撤销功能,没有详细讨论委托和撤销机制。通过分析工作流系统中委托授权特征,提出了一种用户-用户的非单调、多步、确认协议委托授权机制;详细描述了从委托关系定义、判定、实施到撤销的完备的委托过程,形式化地定义了委托条件、委托关系、委托链和委托约束,以及委托和撤销判定规则;给出了委托实施算法和实现此机制的体系架构,以及架构模块间接口的描述。此委托机制可以独立于工作流授权模型实现用户间的委托和委托撤销。

关键词: 工作流, 委托, 授权, 访问控制, 模型

Abstract: Most existing studies on delegation for workflow system were adding delegation and revocation functions in authorization models, there were no detail discussion on delegation and revocation mechanism. By analyzing deligation authorization characteristics of workflow systems, a delegation authorization mechanism which supported non-monotonic, multi-step and bilateral agreement was presented. Then, the delegation implementation process which consisted of delegation relationship definition, assertion, execution and revocation was discussed in detail. Several formal definitions for delegation condition, delegation relationship, delegation chain, delegation constraint, delegation acceptance and revocation rules were provided, and a delegation execution algorithm was put forward. Finally, implementation architecture and the various interfaces among modules and existing workflow system for this mechanism were described. This delegation mechanism could realize delegation and revocation separating from workflow authorization model.

Key words: workflow, delegation, authorization, access control, models

中图分类号: