A technique addressed the problem of security policy is given in this paper . it provides the possibility for addressing it at the system design stage & is interfaced to existing formal specifications and verification methods . tins paper has also shown how access rights can be derived from a petri net workflow dynamically 不仅用数据流图对其视图模型进行了描述,而且用z浯言实现了模型的公式化方法,解决了协同工作中信息在安全级别不同的用户间的流动问题,本文还提出了一种将工作流管理与访问控制相结合的动态访问控制的petri网建模方法,能够实现访问控制的自动化执行并有效提高系统的管理效率。