Protection and administration of XML data sources

被引:11
作者
Bertino, E
Castano, S
Ferrari, E
Mesiti, M
机构
[1] Univ Milan, Dipartimento Sci Informaz, I-20135 Milan, Italy
[2] Univ Insubria, Dipartimento Sci Chim Fis & Matemat, I-22100 Como, Italy
[3] Univ Genoa, Dipartimento Informat & Sci Informaz, I-16146 Genoa, Italy
关键词
XML security; access control; administration facilities; eXcelon DBMS; !text type='Java']Java[!/text;
D O I
10.1016/S0169-023X(02)00127-1
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
EXtensible Markup Language (XML) security has become a relevant research topic due to the widespread use of XML as the language for information interchange and document definition over the Web. In this context, developing an access control mechanism in terms of XML is an important step for Web information security. In this paper, we present the protection and administration facilities of Author-X, a Java-based system for discretionary access control to XML documents. Relevant features of Author-X are both a set-oriented and a document-oriented credential-based document protection, a differentiated protection of document/document type contents through the support of multi-granularity protection objects and positive/negative authorizations, and the support for different access control strategies. In this paper, we focus on the strategies we have developed for enforcing access control. Additionally, we provide a description of the environment we have developed to help the Security Officer in performing administrative activities related to both security policy and subject credential management. (C) 2002 Elsevier Science B.V. All rights reserved.
引用
收藏
页码:237 / 260
页数:24
相关论文
共 10 条
[1]   Securing XML documents with author-X [J].
Bertino, E ;
Castano, S ;
Ferrari, E .
IEEE INTERNET COMPUTING, 2001, 5 (03) :21-31
[2]  
Bertino E., 2001, P SACMAT 2001 ACM S
[3]  
BERTINO E, 2001, P SIGMOD 2001 C SANT
[4]  
DAMIANI E, 2000, P INT C EXT DAT TECH
[5]  
DEUTSCH A, 1999, P INT C WORLD WID WE
[6]  
*OBJ DES INC, 1998, XML DAT SERV BUILD E
[7]  
POLLMANN CG, XML SECURITY PAGE
[8]   An authorization model for a distributed hypertext system [J].
Samarati, P ;
Bertino, E ;
Jajodia, S .
IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 1996, 8 (04) :555-562
[9]  
Stallings W., 2000, Network security essentials : applications and standards
[10]  
WINSLET M, 1997, J COMPUTER SECURITY, V7