跳到主要导航 跳到搜索 跳到主要内容

Compliance Analysis of Authorization Constraints in Business Process

  • Guangxi Normal University

科研成果: 期刊稿件文章同行评审

摘要

A novel framework of business process compliance analysis is proposed in this paper, and the proposed framework can process 1)business process authorization and non-business process authorization; 2)delegation of task of business processes; 3)inheritance of roles; 4)separation of duty and binding of duty constraints; 5)statics constraints and dynamic constraints. Authorization graph is proposed to describe the framework, and construct and reduce methods of authorization graph are designed to maintain the graph, then compliance analysis algorithms of authorization graph are proposed. Based on the analysis results, conflict patterns are presented. A set of resolutions for each pattern are provided, and a prototype system is implemented. The framework of authorization constraint compliance analysis, independent of platform, can be widely applied to system security analyzing. The effectiveness of the proposed method is reported by a case study and experiments at the end of this paper.

源语言英语
页(从-至)2404-2418
页数15
期刊Jisuanji Yanjiu yu Fazhan/Computer Research and Development
54
10
DOI
出版状态已出版 - 1 10月 2017

指纹

探究 'Compliance Analysis of Authorization Constraints in Business Process' 的科研主题。它们共同构成独一无二的指纹。

引用此