首页> 外文期刊>Journal of information science and engineering >Chinese Wall Security Model For Workflow Management Systems with Dynamic Security Policy
【24h】

Chinese Wall Security Model For Workflow Management Systems with Dynamic Security Policy

机译:具有动态安全策略的工作流管理系统的中国墙安全模型

获取原文
获取原文并翻译 | 示例
           

摘要

Secure workflow management systems (WfMSs) are required to support major security features such as authentication, confidentiality, data integrity, and nonrepudiation. The Chinese wall security model (CWSM) was designed to provide access controls that mitigate conflict of interest in commercial organizations, and is especially important for large-scale interenterprise workflow applications. This paper describes how to implement the CWSM in a WfMS. We first demonstrate situations in which an access control model is not sufficient for this if the WfMS does not keep the run-time history of data accesses and company information is mutable, and we then propose an application programming interface (API) to solve this problem, also providing support for the intrinsic dynamic access control mechanism defined in the CWSM (i.e., the dynamic binding of subjects and elements in the company data set). This API can also specify several requirements of the dynamic security policy that arise when applying the CWSM in WfMSs. Finally we discuss how to implement a run-time system to implement CWSM policies specified by this API in a WfMS.
机译:需要安全的工作流管理系统(WfMS)以支持主要的安全功能,例如身份验证,机密性,数据完整性和不可否认性。中国墙安全模型(CWSM)旨在提供缓解商业组织中利益冲突的访问控制,对于大型企业间工作流应用程序尤其重要。本文介绍了如何在WfMS中实现CWSM。我们首先演示了以下情况:如果WfMS无法保持数据访问的运行时历史并且公司信息易变,则访问控制模型不足以解决此问题,然后我们提出一个应用程序编程接口(API)来解决此问题,还为CWSM中定义的内部动态访问控制机制(即公司数据集中主题和元素的动态绑定)提供支持。该API还可以指定在WfMS中应用CWSM时出现的动态安全策略的若干要求。最后,我们讨论如何实现运行时系统以实现WfMS中此API指定的CWSM策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号