Title
Types for task-based access control in workflow systems
Abstract
Task-based access control (TBAC) is a flexible security mechanism, which has been widely implemented in workflow management systems. In TBAC, permissions are assigned to tasks and users can only obtain the permissions during the execution of tasks. The authors aim at developing a method for formalising and analysing security properties of workflow systems under TBAC policy. To achieve this goal, the authors first present WFPI, workflow pi-calculus. By adding task execution and submission primitives, and tagging each agent with its executing and distributing tasks, WFPI can flexibly represent the concepts and elements in workflow systems. Then, based on WFPI, a type system is proposed to ensure that the well-typed workflow systems can abide by the TBAC policy at run time, by avoiding run-time access violations. To the best of onepis knowledge, the present research is the first attempt to study workflow access control by process calculus and types.
Year
DOI
Venue
2008
10.1049/iet-sen:20070098
Software, IET
Keywords
Field
DocType
RESOURCE ACCESS
Workflow technology,Access time,Computer science,Windows Workflow Foundation,Real-time computing,Access control,Workflow engine,Workflow management system,Workflow,Process calculus,Distributed computing
Journal
Volume
Issue
ISSN
2
5
1751-8806
Citations 
PageRank 
References 
1
0.34
11
Authors
3
Name
Order
Citations
PageRank
Lu, Y.143.92
Li Zhang24110.80
Jia-guang Sun31807134.30