University of Warwick
  • Study
  • |
  • Research
  • |
  • Business
  • |
  • Alumni
  • |
  • News
  • Sign in
  • Computer Science Repository
  • More…

    Computer Science Repository

    • Home
    • About
    • Browse by Year
    • Browse by Subject
    • Browse by Division
    • Browse by Author
      • Login

    Modelling Workflow Executions Under Role-based Authorisation Control

    He, L., Duan, K., Chen, X., Zou, D., Han, Z., Fadavinia, A. and Jarvis, S.A. (2011) Modelling Workflow Executions Under Role-based Authorisation Control. In: 8th IEEE International Conference on Services Computing (ICSC'11), 4-9th July 2011, Washington DC, USA.

    [img]
    Preview
    PDF - Draft Version
    Download (2319Kb) | Preview

      Abstract

      Workflows are often used to represent enterprise-type activities, and authorisation control is an important security consideration in enterprise-level applications. Role-Based Access Control (RBAC) is a popular authorisation control scheme under which users are assigned to certain roles, and the roles are associated with permissions. This paper presents a novel mechanism for modelling workflow execution in cluster-based resource pools under Role-Based Access Control (RBAC) schemes. Our modelling approach uses Coloured Timed Petri-Nets, and various authorisation constraints are modelled, including role constraints, temporal constraints, cardinality constraints, Binding of Duty and Separation of Duty constraints, etc. The interactions between workflow authorisation and workflow execution are also captured in the model. In this paper, the modelling mechanism is developed in such a fashion that the construction of the authorisation model for a workflow can be automated. This feature is very helpful in modelling a large collection of authorisation policies or complex workflows. A Petri-net simulation tool, the CPN-Tool, is utilised to implement the developed modelling mechanism and simulate the constructed model. Both system-level performance (e.g., utilisation of resource pools) and application-level performance (e.g., workflow response time) can be obtained from model simulations. This work can be used to plan system capacity and investigate the impact of authorization policies on system and application performance.

      Item Type: Conference or Workshop Item (Paper)
      Uncontrolled Keywords: pcav hpsg business transaction ebusiness internet workflow authentication
      Subjects: Q Science > QA Mathematics > QA76 Computer software
      Q Science > QA Mathematics > QA76.73 Computer algorithms. Data structures.
      Divisions: Faculty of Science > Computer Science
      Depositing User: Matt Leeke
      Date Deposited: 03 May 2011 11:03
      Last Modified: 23 Feb 2012 09:08
      URI: http://eprints.dcs.warwick.ac.uk/id/eprint/645

      Actions (login required)

      View Item
      Close this email form
      Page contact: Repository administrator Last revised: Wed 21 Mar 2012
      • Sign in
      • | Powered by EPrints 3