• 论文 •    

基于角色的工作流授权约束规格说明

于万钧,, 刘大有, 刘  全, 李嘉菲,   

  1. 1.东北电力学院 信息工程系, 吉林  吉林  132012;2.吉林大学 计算机科学与技术学院, 吉林  长春  130021;3.吉林大学 符号计算与知识工程教育部重点实验室,吉林  长春  130012
  • 出版日期:2005-09-15 发布日期:2005-09-25

Specification of role-based authorization constraints in workflow management systems

YU Wan-jun,, LIU Da-you,, LIU Quan,, LI Jia-fei,   

  1. 1.Dep. of Info. Eng., Northeast China Inst. of Electric Power Eng., Jilin  132012, China;2.Sch. of Computer Sci.&Tech., Jilin Univ., Changchun  130012, China;3.Key Lab. of Symbolic Computation and Knowledge Eng. of Ministry of Education,Jilin Univ., Changchun  130012, China
  • Online:2005-09-15 Published:2005-09-25

摘要: 在工作流管理系统中,数据在工作流任务中流动,执行任务的用户在变化,用户的权限也在变化,现有的授权方法不能很好地描述上述这种职责分离的状态。为此,提出了一个工作流授权约束模型。该模型在工作流应用语境中定义了角色层次函数、任务偏序关系和互斥任务,在此基础上给出了一个基于角色的工作流授权约束语言,它可以准确描述工作流系统的职责分离要求,表达静态、动态授权约束和授权的历史信息,同时,所得到的约束规则集规模相对较小,保证了一致性验证在时间和空间上的可行性。

关键词: 工作流, 工作流管理系统, 角色, 授权约束

Abstract: The existing approaches of authorization constraints cannot describe the separation of duties well in the workflow management systems under which with the data movement from one task to next, and the change of task executors and users access control at any moment. To solve this problem, a model of workflow authorization constraints was proposed. The role level function, the task partial relationship and the conflicting tasks in the context of workflow application were defined in the model. Based on the model, a language named role-task-based Workflow Authorization Language (WAL) was put forward to specify the workflow authorization constraints. The requests on the separation of duties in the workflow system could be correctly described by WAL. Static and authorized historical information could also be expressed. Meanwhile, the size of rules set obtained was relatively smaller. Finally the feasibility of the consistency validation in the time and the space was verified.

Key words: workflow, workflow management systems, role, authorization constraints

中图分类号: