A workflow-based RBAC model for web services (WFRBAC4WS) has been proposed in this paper. The model organizes web services in different autonomous domains through workflow mechanism, and maps RBAC model to tasks of workflow model. The paper details the authorization procedure of WFRBAC4WS model, the lifetime management, the extension of authorization constraint and the formal descriptions of the proposed model. Compared with other RBAC models for web services, this model not only combines RBAC model to workflow, but also describes the interactions between workflow mechanism and RABC model in web services environment, the authorization work of this model is dynamically and comprehensively.
Read full abstract