An object-oriented organizational model to support dynamic role-based access control in electronic commerce

作者:

摘要

Role-based access control (RBAC) provides flexibility to security management over the traditional approach of using user and group identifiers. In RBAC, access privileges are given to roles rather than to individual users. Users acquire the corresponding permissions when playing different roles. Roles can be defined simply as a label, but such an approach lacks the support to allow users to automatically change roles under different contexts; using static method also adds administrative overheads in role assignment. In electronic commerce (E-Commerce) and other cooperative computing environments, access to shared resources has to be controlled in the context of the entire business process; it is therefore necessary to model dynamic roles as a function of resource attributes and contextual information.

论文关键词:Electronic commerce,Role-based access control,Organization modeling,Role resolution,Business process management,Workflow

论文评审过程:Available online 8 September 2000.

论文官网地址:https://doi.org/10.1016/S0167-9236(00)00083-X