书目名称 | Information Flow Based Security Control Beyond RBAC |
副标题 | How to enable fine-g |
编辑 | Klaus-Peter Fischer-Hellmann,Rainer Bischoff |
视频video | |
概述 | Comprehensible for experts in the field as well as other readers.Providing modern methods of information flow control.Easy-to-apply and proven methods.Includes supplementary material: .Includes supple |
丛书名称 | IT im Unternehmen |
图书封面 |  |
描述 | Role-based access control (RBAC) is a widely used technology to control information flows as well as control flows within and between applications in compliance with restrictions implied by security policies, in particular, to prevent disclosure of information or access to resources beyond restrictions defined by those security policies. Since RBAC only provides the alternatives of either granting or denying access, more fine-grained control of information flows such as “granting access to information provided that it will not be disclosed to targets outside our organisation during further processing” is not possible. In business processes, in particular those spanning several organisations, which are commonly defined using business process execution language (BPEL), useful information flows not violating security policy-implied limitations would be prevented if only the access control capabilities offered by RBAC are in use. The book shows a way of providing more refined methods of information flow control that allow for granting access to information or resources by taking in consideration the former or further information flow in a business process requesting this access. The me |
出版日期 | Book 2012 |
关键词 | Access Control; Cooperative Business Processes; Information Flow Control; Security Policy Enforcement; W |
版次 | 1 |
doi | https://doi.org/10.1007/978-3-8348-2618-3 |
isbn_softcover | 978-3-8348-2617-6 |
isbn_ebook | 978-3-8348-2618-3Series ISSN 2522-0608 Series E-ISSN 2522-0616 |
issn_series | 2522-0608 |
copyright | Vieweg+Teubner Verlag | Springer Fachmedien Wiesbaden 2012 |