28th Annual International Computer Software and Applications Conference (COMPSAC'04)
SOWAC: A Service-Oriented Workflow Access Control Model
Hong Kong
September 28-September 30
ISBN: 0-7695-2209-2
Workflow access control is the fundamental issue in workflow security. With the development of enterprise globalization and the constant re-engineering and optimizing of enterprise business, the organization becomes more dynamic and its business process is frequently changing. As a result, workflow access control turns more complicated and entails a comparatively operational mechanism. To solve the problem, in view of decoupling workflow access control model from workflow model, we propose a Service-Oriented Workflow Access Control (SOWAC) model in this paper. In SOWAC model, service is the abstraction of a task and the unit for applying access control. We present the elements of SOWAC model and illustrate the enforcement of SOWAC with an example workflow. Then the dynamic separation of duty for SOWAC model is proposed based on the authorization history of services. By applying SOWAC in a real workflow management system, we show SOWAC model is practical and effectual.
Citation:
Wei Xu, Jun Wei, Yu Liu, Jing Li, "SOWAC: A Service-Oriented Workflow Access Control Model," compsac, vol. 1, pp.128-134, 28th Annual International Computer Software and Applications Conference (COMPSAC'04), 2004