Unified Implementation and Simplification for Task-Based Authorization Security in Workflows

被引:0
|
作者
Zhong, Wenjing [1 ,2 ]
Zhao, Jinjing [2 ]
Hu, Hesuan [1 ,3 ,4 ]
机构
[1] Xidian Univ, Sch Electromech Engn, Xian 710071, Shaanxi, Peoples R China
[2] Natl Key Lab Sci & Technol Informat Syst Secur, Beijing 100101, Peoples R China
[3] Nanyang Technol Univ, Sch Comp Sci & Engn, Coll Engn, Singapore 639798, Singapore
[4] Xi An Jiao Tong Univ, State Key Lab Mfg Syst Engn, Xian 710054, Shaanxi, Peoples R China
关键词
Security; Task analysis; Authorization; Computational modeling; Monitoring; Modeling; Organizations; Workflow management systems; task-based authorization security; implementation and simplification; Petri nets; ACCESS-CONTROL; PETRI NETS; CONSTRAINTS; REQUIREMENTS; ENVIRONMENTS; SEPARATION; MODEL;
D O I
10.1109/TSC.2023.3268651
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Authorization-related security requirements are of great significance in workflow management systems. Existing studies are restricted in their scopes of research. There is no unified principle for their implementation. In this paper, we focus on the unification of authorization-related security requirements using Petri nets (PNs). These security requirements are expressed by constraints, being imposed on tasks, namely task-based security requirements (TSRs). By downgrading TSRs to a kind of authorization-conflict relationship, we provide a standardized expression for TSRs. Such a standardized expression can be transformed to firing-based linear inequalities which are a more general representation of constraints. Then, we propose the firing control for the unified implementation of TSRs based on firing-based linear inequalities. In fact, firing control is enforced by structural controllers namely monitors which are structurally consistent with PNs. For the sake of conciseness, simplification techniques are provided for the monitors. Ultimately, the experiments and discussions are presented to show the performance and advantages of the proposed approach.
引用
收藏
页码:3796 / 3811
页数:16
相关论文
共 50 条
  • [21] Task-based memory systems in contextual-cueing of visual search and explicit recognition
    Geyer, Thomas
    Rostami, Pardis
    Sogerer, Lisa
    Schlagbauer, Bernhard
    Mueller, Hermann J.
    SCIENTIFIC REPORTS, 2020, 10 (01)
  • [22] Modelling and Verification of Interorganizational Workflows with Security Constraints: A Petri Nets-Based Approach
    Captarencu, Oana Otilia
    ADVANCED INFORMATION SYSTEMS ENGINEERING WORKSHOPS, CAISE 2012, 2012, 112 : 486 - 493
  • [23] A Security Framework for IoT Authentication and Authorization based on Blockchain Technology
    Pajooh, Houshyar Honar
    Rashid, M. A.
    2019 18TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS/13TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (TRUSTCOM/BIGDATASE 2019), 2019, : 264 - 271
  • [24] Applying Security Patterns for authorization of users in IoT Based Applications
    Ali, Ishfaq
    Asif, Muhammad
    2018 INTERNATIONAL CONFERENCE ON ENGINEERING & EMERGING TECHNOLOGIES (ICEET), 2018, : 77 - 81
  • [25] A VO-based Security Architecture for Authentication and Authorization in Grid
    Yang, Yan
    Chen, Xingyuan
    Zhang, Bin
    Li, Binglong
    2009 INTERNATIONAL CONFERENCE ON E-BUSINESS AND INFORMATION SYSTEM SECURITY, VOLS 1 AND 2, 2009, : 986 - 990
  • [26] SAMGRID: Security Authorization and Monitoring Module Based on SealedGRID Platform
    Suciu, George
    Farao, Aristeidis
    Bernardinetti, Giorgio
    Palama, Ivan
    Sachian, Mari-Anais
    Vulpe, Alexandru
    Vochin, Marius-Constantin
    Muresan, Pavel
    Bampatsikos, Michail
    Munoz, Antonio
    Xenakis, Christos
    SENSORS, 2022, 22 (17)
  • [27] Task-Based Information Interaction Evaluation: The Viewpoint of Program Theory
    Jarvelin, Kalervo
    Vakkari, Pertti
    Arvola, Paavo
    Baskaya, Feza
    Jarvelin, Anni
    Kekalainen, Jaana
    Keskustalo, Heikki
    Kumpulainen, Sanna
    Saastamoinen, Miamaria
    Savolainen, Reijo
    Sormunen, Eero
    ACM TRANSACTIONS ON INFORMATION SYSTEMS, 2015, 33 (01)
  • [28] A Task-Based Model for the Lifespan of Peer-to-Peer Swarms
    Zhao, Yong
    Zhang, Zhibin
    He, Ting
    Liu, Alex X.
    Guo, Li
    Fang, Binxing
    NETWORKING 2012, PT II, 2012, 7290 : 71 - 83
  • [29] Realtime hybrid task-based control for robots and machine tools
    Soetens, P
    Bruyninckx, H
    2005 IEEE INTERNATIONAL CONFERENCE ON ROBOTICS AND AUTOMATION (ICRA), VOLS 1-4, 2005, : 259 - 264
  • [30] Task-based design of cable-driven articulated mechanisms
    Li, Jian
    Andrews, Sheldon
    Birkas, Krisztian G.
    Kry, Paul G.
    PROCEEDINGS SCF 2017: ACM SYMPOSIUM ON COMPUTATIONAL FABRICATION, 2017,