Satisfiability and Feasibility in a Relationship-Based Workflow Authorization Model

Satisfiability and Feasibility in a Relationship-Based Workflow Authorization Model
复制标题

基于关系的工作流授权模型的可满足性和可行性

DOI:
--
复制
发表时间:
2012
期刊:
European Symposium on Research in Computer Security
影响因子:
--
通讯作者:
Philip W. L. Fong
Philip W. L. Fong
中科院分区:
--
文献类型:
--
作者:
A. A. Khan;Philip W. L. Fong

文献摘要

被引文献

相似文献

在ReBAC框架下定义了一种工作流授权模型,其中保护状态为社会网络。在此基础上,我们研究了一个新的决策问题--工作流可行性问题。目标是确保保护状态空间包含至少一个成员,其中工作流规范可以执行完成。我们确定了一个充分条件下,可行性可以决定由一个反驳程序,这是健全的和完整的。提出了一种基于命题动态逻辑(PDL)单调片段的形式化描述语言,用于描述保护状态空间。该语言的采用使得工作流的可行性在一般情况下是NP完全的,但对于一个重要的工作流家族是多项式时间可判定的。
A workflow authorization model is defined in the framework of Relationship-Based Access Control (ReBAC), in which the protection state is a social network. Armed with this model, we study a new decision problem called workflow feasibility. The goal is to ensure that the space of protection states contains at least one member in which the workflow specification can be executed to completion. We identify a sufficient condition under which feasibility can be decided by a refutation procedure that is both sound and complete. A formal specification language, based on a monotonic fragment of the Propositional Dynamic Logic (PDL), is proposed for specifying protection state spaces. The adoption of this language renders workflow feasibility NP-complete in the general case but polynomial-time decidable for an important family of workflows.