Title: Enforcing access control in workflow systems with a task engineering approach

Authors: Hamid Hatim; Hanan El Bakkali; Ilham Berrada

Addresses: Université Mohammed V-Souissi, ENSIAS, BP: 713, Agdal – Rabat, Morocco. ' Université Mohammed V-Souissi, ENSIAS, BP: 713, Agdal – Rabat, Morocco. ' Université Mohammed V-Souissi, ENSIAS, BP: 713, Agdal – Rabat, Morocco

Abstract: The need for 'role engineering' becomes evident once a decision has been made to adopt role-based access control (RBAC) to ensure access control in a computer system. Role engineering is a process to define roles, permissions, and role hierarchies. Therefore, it is a critical step in deploying any RBAC-oriented system. The question is even more crucial for workflow management systems: additionally to role engineering, a 'task engineering' process could be needed to allow the satisfaction of access control constraints even in critical situations. In this paper, we propose an approach of task engineering to improve access control enforcement in workflow management systems. By task engineering, we mean the process to examine the granularity of each workflow's task in a way to meet – at run time – the main access control requirements, precisely the least privilege and separation of duties principles. This approach uses the constraints satisfaction problem (CSP) formulation and resolution method.

Keywords: workflow; role-based access control; RBAC; role engineering; task engineering; granulatrity; atomicity; constraints satisfaction problem; CSP.

DOI: 10.1504/IJITST.2012.045150

International Journal of Internet Technology and Secured Transactions, 2012 Vol.4 No.1, pp.55 - 70

Available online: 26 Jan 2012 *

Full-text access for editors Access for subscribers Purchase this article Comment on this article