Apply measurable risk to strengthen security of a role-based delegation supporting workflow system

  • Authors:
  • Weili Han;Qun Ni;Hong Chen

  • Affiliations:
  • Software School, Fudan University, Shanghai, China and Department of Computer Science, Purdue University, West Lafayette, Indiana;Department of Computer Science, Purdue University, West Lafayette, Indiana;Department of Computer Science, Purdue University, West Lafayette, Indiana

  • Venue:
  • POLICY'09 Proceedings of the 10th IEEE international conference on Policies for distributed systems and networks
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Workflow systems often use delegation to enhance the flexibility of authorization. However, using delegation also weakens security because users may have difficulties understand and design correct delegation policies. In this paper. we propose the Measurable Risk Adaptive Role-based Delegation (MRARD) framework to address this problem. MRARD employs measurable risk for SSOs (System Security Officers) to provide a complementary protection mechanism in role-based delegation supporting workflow systems. In MRARD, when another enterprise user wants to use a delegated role to execute a task, a fuzzy logic based inference processor will infer the risk_level. Based on simple risk adaptive decision policies, a decision module will determine whether the access should be granted under a certain risk mitigation action.