计算机应用 ›› 2011, Vol. 31 ›› Issue (03): 778-780.DOI: 10.3724/SP.J.1087.2011.00778

• 信息安全 • 上一篇    下一篇

基于组和角色的工作流权限访问控制模型

于春生,聂晶   

  1. 大庆油田有限责任公司 第八采油厂,黑龙江 大庆163514
  • 收稿日期:2010-08-31 修回日期:2010-10-10 发布日期:2011-03-03 出版日期:2011-03-01
  • 通讯作者: 于春生
  • 作者简介:于春生(1979-),男,山东日照人,工程师,硕士,主要研究方向:分布式计算、GIS、信息集成应用、工作流;聂晶(1978-),女,黑龙江大庆人,工程师,硕士,主要研究方向:地球探测、信息技术。

Access control model of workflow permission based on group and role

YU Chun-sheng,NIE Jing   

  1. No.8 Oil Production Company, Daqing Oil Company Limited, Daqing Helongjiang 163514, China
  • Received:2010-08-31 Revised:2010-10-10 Online:2011-03-03 Published:2011-03-01
  • Contact: YU Chun-sheng

摘要: 基于角色的权限控制已经作为国际规范被广泛应用,但是它只能解决用户对某一操作环境的操作权限问题,无法解决相同操作环境下对不同客体子集的访问控制问题,特别是在工作流系统中,对不同对象集、不同节点的权限访问控制尤为重要。针对这个问题,对基于角色的权限控制技术和工作流技术进行了研究,提出了基于组/角色的工作流权限访问控制模型,实现了对操作对象集、操作权限集的二维权限控制,很好地解决了跨区域情况下,多部门基于工作流系统工作时的对象访问控制和权限控制问题。目前该模型已经成功应用于油田作业施工的一体化办公系统中,实践证明该模型的设计是科学合理的、可行的。

关键词: 组, 角色, 工作流, 权限

Abstract: Role-based Access Control (RBAC) has been widely used as an international norm, but it can only give users authority to operate a particular operating environment issues, and it cannot be used to solve the access control problems of different subsets of operating objects under same conditions. Especially in the workflow system, access control of different set of objects, and different nodes is particularly important. To address this problem, role-based access control technique and workflow technique were studied. An access control model of workflow permissions was proposed based on group/role, which achieved two-dimensional operation set access control permissions. It is a better solution to the cross-regional case, the multi-sector work-based workflow system object access control and access control problems. Currently, the model has been used in the construction of oilfield integration system, and the application shows that the model is scientific, reasonable and feasible.

Key words: group, role, workflow, permission

中图分类号: