Perti Net-Based Workflow Access Control Model

Access control is an important protection mechanism for information systems. This paper shows how to make access control in workflow system. We give a workflow access control model (WACM) based on several current access control models. The model supports roles assignment and dynamic authorization. The paper defines the workflow using Petri net. It firstly gives the definition and description of the workflow, and then analyzes the architecture of the workflow access control model (WACM). Finally, an example of an e-commerce workflow access control model is discussed in detail.

[1]  Shengli Wu,et al.  Authorization and Access Control of Application Data in Workflow Systems , 2004, Journal of Intelligent Information Systems.

[2]  Tadao Murata,et al.  Petri nets: Properties, analysis and applications , 1989, Proc. IEEE.

[3]  Vijayalakshmi Atluri,et al.  SecureFlow: a secure Web-enabled workflow management system , 1999, RBAC '99.

[4]  Konstantin Knorr,et al.  Dynamic access control through Petri net workflows , 2000, Proceedings 16th Annual Computer Security Applications Conference (ACSAC'00).

[5]  Ravi S. Sandhu,et al.  Task-Based Authorization Controls (TBAC): A Family of Models for Active and Enterprise-Oriented Autorization Management , 1997, DBSec.

[6]  Joon S. Park,et al.  Access control mechanisms for inter-organizational workflow , 2001, SACMAT '01.

[7]  Deng Ji Task-Based Access Control Model , 2003 .

[8]  Ravi S. Sandhu,et al.  Role-based Administration of User-Role Assignment: The URA97 Model and its Oracle Implementation , 1999, J. Comput. Secur..

[9]  Vijayalakshmi Atluri,et al.  A Petri net based safety analysis of workflow authorization models^1 , 2000 .

[10]  David M. Eyers,et al.  Shielding RBAC Infrastructures from Cyberterrorism , 2002, DBSec.

[11]  Amit P. Sheth,et al.  A Multilevel Secure Workflow Management System , 1999, CAiSE.

[12]  Hong Fan A TASK-BASED AUTHORIZATION MODEL , 2002 .

[13]  Wil M. P. van der Aalst,et al.  The Application of Petri Nets to Workflow Management , 1998, J. Circuits Syst. Comput..

[14]  Vijayalakshmi Atluri,et al.  Modeling and Analysis of Workflows Using Petri Nets , 1998, Journal of Intelligent Information Systems.