基于信任的工作流访问控制策略研究

Rui Ma, Linying Xu, Pengxiang Gao
{"title":"基于信任的工作流访问控制策略研究","authors":"Rui Ma, Linying Xu, Pengxiang Gao","doi":"10.1109/WISA.2014.24","DOIUrl":null,"url":null,"abstract":"The traditional workflow access control strategy has often found to be inadequate to detect and restrain malicious behavior effectively. With the aim to solve this problem, this paper presents a new workflow access control model based on trust, and a new access control strategy with an authorization process. This strategy introduces user behavior evaluation, trust computation and role hierarchy into role access control strategy. Through the trust computation of user behavior, it can dynamically adjust user's role and permissions, realizing the dynamic authorization process. Theory analysis and simulation experiments show that this access control strategy is more sensitive in dynamic authorization, and it has fine-grained trust computation. Also this strategy can detect malicious behaviors in time, effectively restraining malicious behavior harming the system so enhancing the security of the system.","PeriodicalId":366169,"journal":{"name":"2014 11th Web Information System and Application Conference","volume":"39 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-09-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Research of Workflow Access Control Strategy based on Trust\",\"authors\":\"Rui Ma, Linying Xu, Pengxiang Gao\",\"doi\":\"10.1109/WISA.2014.24\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The traditional workflow access control strategy has often found to be inadequate to detect and restrain malicious behavior effectively. With the aim to solve this problem, this paper presents a new workflow access control model based on trust, and a new access control strategy with an authorization process. This strategy introduces user behavior evaluation, trust computation and role hierarchy into role access control strategy. Through the trust computation of user behavior, it can dynamically adjust user's role and permissions, realizing the dynamic authorization process. Theory analysis and simulation experiments show that this access control strategy is more sensitive in dynamic authorization, and it has fine-grained trust computation. Also this strategy can detect malicious behaviors in time, effectively restraining malicious behavior harming the system so enhancing the security of the system.\",\"PeriodicalId\":366169,\"journal\":{\"name\":\"2014 11th Web Information System and Application Conference\",\"volume\":\"39 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2014-09-12\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2014 11th Web Information System and Application Conference\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/WISA.2014.24\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 11th Web Information System and Application Conference","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WISA.2014.24","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

传统的工作流访问控制策略往往不能有效地检测和抑制恶意行为。针对这一问题,本文提出了一种新的基于信任的工作流访问控制模型和一种新的带有授权过程的访问控制策略。该策略在角色访问控制策略中引入了用户行为评估、信任计算和角色层次。通过对用户行为的信任计算,动态调整用户的角色和权限,实现动态授权过程。理论分析和仿真实验表明,该访问控制策略对动态授权更敏感,并且具有细粒度的信任计算。该策略可以及时发现恶意行为,有效地抑制对系统造成危害的恶意行为,从而提高系统的安全性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Research of Workflow Access Control Strategy based on Trust
The traditional workflow access control strategy has often found to be inadequate to detect and restrain malicious behavior effectively. With the aim to solve this problem, this paper presents a new workflow access control model based on trust, and a new access control strategy with an authorization process. This strategy introduces user behavior evaluation, trust computation and role hierarchy into role access control strategy. Through the trust computation of user behavior, it can dynamically adjust user's role and permissions, realizing the dynamic authorization process. Theory analysis and simulation experiments show that this access control strategy is more sensitive in dynamic authorization, and it has fine-grained trust computation. Also this strategy can detect malicious behaviors in time, effectively restraining malicious behavior harming the system so enhancing the security of the system.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信