ACM Home Page
Please provide us with feedback. Feedback
Supporting conditional delegation in secure workflow management systems
Full text PdfPdf (256 KB)
Source Symposium on Access Control Models and Technologies archive
Proceedings of the tenth ACM symposium on Access control models and technologies table of contents
Stockholm, Sweden
SESSION: Access control model II table of contents
Pages: 49 - 58  
Year of Publication: 2005
ISBN:1-59593-045-0
Authors
Vijayalakshmi Atluri  Rutgers University, Newark, NJ
Janice Warner  Rutgers University, Newark, NJ
Sponsors
ACM: Association for Computing Machinery
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 16,   Downloads (12 Months): 75,   Citation Count: 8
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1063979.1063990
What is a DOI?

ABSTRACT

Workflows model and control the execution of business processes in an organization. A workflow typically comprises of a set of coordinated activities, known as tasks. Typically, organizations establish a set of security policies, that regulate how the business process and resources should be managed. While a simple policy may specify which user (or role) can be assigned to execute a task, a complex policy may specify authorization constraints, such as separation of duties. Users may delegate the tasks assigned to them. Often such delegations are short-lived and come into play when certain conditions are satisfied. For example, a user may want to delegate his task of check approval only when going on vacation, when a check amount is less than a certain amount, or when his workload exceeds a certain limit.In this paper, we extend the notion of delegation to allow for such conditional delegation, where the delegation conditions can be based on time, workload and task attributes. When workflow systems entertain conditional delegation, different types of constraints come into play, which include authorization constraints, role activation constraints and workflow dependency requirements. We address the problem of assigning users to tasks in a consistent manner such that none of the constraints are violated.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
 
2
V. Atluri, E. Bertino, E. Ferrari, P. Mazzoleni, Supporting Delegation in Secure Workflow Management Systems. In IFIP WG 11.3 Conference on Data and Application Security, August 2003.
 
3
E. Barka and R. Sandhu. Framework for role-based delegation model. In Proceedings of 23rd National Information Systems Security Conference, pages 101-- 114, October 2000.
4
5
 
6
 
7
D. D. Clark and D. R. Wilson. A comparison of commercial and military computer security policies. In Proc. IEEE Symposium on Security and Privacy, pages 184--194, Oakland, California, April 1987.
8
 
9
M. Gasser and E. McDermott. An architecture for practical delegation of a distributed system. In Proc. IEEE Symposium on Security and Privacy, May 1990.
 
10
 
11
D. Hollingsworth, Workflow reference model, Technical report WfMC-TC-1003, Workflow Management Coalition, January 1994.
 
12
 
13
 
14
 
15
R. Sandhu. Separation of Duties in Computerized Information Systems. In Database Security IV: Status and Prospects, pages 179--189, 1991.
 
16
17
18

CITED BY  8

Collaborative Colleagues:
Vijayalakshmi Atluri: colleagues
Janice Warner: colleagues