An access control mechanism for large scale data dissemination systems

被引:3
作者
Bertino, E [1 ]
Ferrari, E [1 ]
Pitoura, E [1 ]
机构
[1] Univ Milan, Dept Comp Sci, Milan, Italy
来源
ELEVENTH INTERNATIONAL WORKSHOP ON RESEARCH ISSUES IN DATA ENGINEERING, PROCEEDINGS: DOCUMENT MANAGEMENT FOR DATA INTENSIVE BUSINESS AND SCIENTIFIC APPLICATIONS | 2001年
关键词
D O I
10.1109/RIDE.2001.916490
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Automatic data dissemination systems are becoming increasingly relevant in internet-based information systems. In such systems, users subscribe to the dissemination service by providing interest profiles. These profiles are then used to determine which information should be delivered to which users, whenever new information is entered into the system. A main shortcoming of existing dissemination systems is the lack of any access control mechanisms, enabling selective information dissemination based for example on security or other regulatory policies. In this paper, we present an access control model suitable for dissemination systems. The model is based on user profiles containing both user interests and user credentials (i.e., a set of attributes characterizing users for access control purposes). information is then filtered before being delivered to users on the basis of both the user interests and credentials. To make authorization manageable when dealing with very large information systems, our model supports authorization domains, that allow one to group together information objects to which the same access control policies apply. Finally, in addition to formally defining our model and developing the related access control algorithm, we outline an implementation strategy.
引用
收藏
页码:43 / 50
页数:8
相关论文
共 10 条
[1]  
*ACM, 1996, P 1 ACM WORKSH ROL B
[2]  
BERTINO E, 2000, ACCESS CONTROL MECH
[3]  
GIFFORD D, 1985, P S OP SYST PRINC, P161
[4]   USING COLLABORATIVE FILTERING TO WEAVE AN INFORMATION TAPESTRY [J].
GOLDBERG, D ;
NICHOLS, D ;
OKI, BM ;
TERRY, D .
COMMUNICATIONS OF THE ACM, 1992, 35 (12) :61-70
[5]  
HOLOWCZAK R, 1997, THESIS RUTGERS U
[6]   WVTDB - A semantic content-based video database system on the World Wide Web [J].
Jiang, HT ;
Elmagarmid, AK .
IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 1998, 10 (06) :947-966
[7]   An authorization model for a distributed hypertext system [J].
Samarati, P ;
Bertino, E ;
Jajodia, S .
IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 1996, 8 (04) :555-562
[8]  
TAK HGM, 1994, ACM TODS, V19, P332
[9]  
WINSLETT M, 1997, J COMPUTER SECURITY, V5
[10]   The SIFT information dissemination system [J].
Yan, TW ;
Garcia-Molina, H .
ACM TRANSACTIONS ON DATABASE SYSTEMS, 1999, 24 (04) :529-565