Microservice-based ERP systems face the challenge of providing a consistent authorization and delegation mechanism to control actions on resources for different authorities, including their users and the services they use or connect to. These challenges arise due to the complex and varied requirements of different business management models, such as position-based, task-based, or hybrid models. This paper proposes a simple, unified delegated authorization model that allows for defining authorization and delegation policies based on controlled actions by entities on objects, using predefined and customizable attributes related to positions, tasks, and organizational policies applied to the authorities. Building on this model, we introduce a framework that addresses the need for a consistent and manageable delegation process and an efficient handling of dynamic authorization and delegation requirements for both users and services across the ERP system. The framework consists of four key components: authorization controller, delegation controller, policy controller, and attribute controller. It enables the retrieval of attributes for authorization checks and the establishment of delegation. The framework is integrated into a microservice-based ERP system and experimented with real-world authorities, demonstrating its effectiveness in making access control and delegation decisions on their actions.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Towards a Unified Delegated Authorization Framework for Microservice-Based ERP Systems

  • Thi-Huong-Giang Vu,
  • Duc-Lam Dinh

摘要

Microservice-based ERP systems face the challenge of providing a consistent authorization and delegation mechanism to control actions on resources for different authorities, including their users and the services they use or connect to. These challenges arise due to the complex and varied requirements of different business management models, such as position-based, task-based, or hybrid models. This paper proposes a simple, unified delegated authorization model that allows for defining authorization and delegation policies based on controlled actions by entities on objects, using predefined and customizable attributes related to positions, tasks, and organizational policies applied to the authorities. Building on this model, we introduce a framework that addresses the need for a consistent and manageable delegation process and an efficient handling of dynamic authorization and delegation requirements for both users and services across the ERP system. The framework consists of four key components: authorization controller, delegation controller, policy controller, and attribute controller. It enables the retrieval of attributes for authorization checks and the establishment of delegation. The framework is integrated into a microservice-based ERP system and experimented with real-world authorities, demonstrating its effectiveness in making access control and delegation decisions on their actions.