KEYWORDS: Information security, Control systems, Process modeling, Systems modeling, Distributed computing, Defense and security, Computer security, Legal, Computing systems, Performance modeling
The traditional mandatory access control policy (MAC) is regarded as a policy with strict regulation and poor flexibility.
The security policy of MAC is so compelling that few information systems would adopt it at the cost of facility, except
some particular cases with high security requirement as military or government application. However, with the
increasing requirement for flexibility, even some access control systems in military application have switched to role-based
access control (RBAC) which is well known as flexible. Though RBAC can meet the demands for flexibility but it
is weak in dynamic authorization and consequently can not fit well in the workflow management systems. The task-role-based
access control (T-RBAC) is then introduced to solve the problem. It combines both the advantages of RBAC and
task-based access control (TBAC) which uses task to manage permissions dynamically. To satisfy the requirement of
system which is distributed, well defined with workflow process and critically for time accuracy, this paper will analyze
the spirit of MAC, introduce it into the improved T&RBAC model which is based on T-RBAC. At last, a conceptual
task-role-based access control model with high security for distributed workflow and real-time application
(A_T&RBAC) is built, and its performance is simply analyzed.
Access to the requested content is limited to institutions that have purchased or subscribe to SPIE eBooks.
You are receiving this notice because your organization may not have SPIE eBooks access.*
*Shibboleth/Open Athens users─please
sign in
to access your institution's subscriptions.
To obtain this item, you may purchase the complete book in print or electronic format on
SPIE.org.
INSTITUTIONAL Select your institution to access the SPIE Digital Library.
PERSONAL Sign in with your SPIE account to access your personal subscriptions or to use specific features such as save to my library, sign up for alerts, save searches, etc.