The Delegation Authorization Model: A Model for the Dynamic Delegation of Authorization Rights in a Secure Workflow Management System
Venter and Olivier
2002
Citation information
K. Venter and M. S. Olivier. “The Delegation Authorization Model: A Model for the Dynamic Delegation of Authorization Rights in a Secure Workflow Management System”. In: ISSA2002. Published electronically. Muldersdrift, South Africa, 2002Abstract
A workflow is a coordinated arrangement of related tasks in an automated process, the systematic execution of which, ultimately achieves some goal. Tasks that comprise the workflow process are typically dependent on one another. Security, in a workflow context, involves the implementation of access control security mechanisms to ensure that task dependencies are coordinated and that tasks are performed by authorized subjects only. A Workflow Authorization Model (WAM) [AH96b] has already been developed to enforce security principles on workflows, by addressing the granting and revoking of authorizations in a Workflow Management System (WFMS). This WAM satisfies most criteria required for an optimal access control model for workflows, some of which cannot be met through pure role-based access control (RBAC) mechanisms. This paper addresses the delegation of task authorizations within a workflow process by subjects in the organizational structure. The proposed The Delegation Authorization Model (DAM) will work within the security constraints imposed by the WAM when deciding whether delegations will be approved or denied. It will also take into account the dynamically determined constraints imposed by the DAM itself.
Full text
A pre- or postprint of the publication is available at https://mo.co.za/open/wf-dam.pdf.BibTeX reference
@inproceedings(wf-dam,author={Karin Venter and Martin S Olivier},
title={The {D}elegation {A}uthorization {M}odel: A Model for the Dynamic Delegation of Authorization Rights in a Secure Workflow Management System},
booktitle={ISSA2002},
address={Muldersdrift, South Africa},
year={2002},
note={Published electronically} )