Efficient database-driven evaluation of security clearance for federated access control of dynamic XML documents

Erwin Leonardi, Sourav S. Bhowmick, Mizuho Iwaihara

研究成果: Conference contribution

4 被引用数 (Scopus)

抄録

Achieving data security over cooperating web services is becoming a reality, but existing XML access control architectures do not consider this federated service computing. In this paper, we consider a federated access control model, in which Data Provider and Policy Enforcers are separated into different organizations; the Data Provider is responsible for evaluating criticality of requested XML documents based on co-occurrence of security objects, and issuing security clearances. The Policy Enforcers enforce access control rules reflecting their organization-specific policies. A user's query is sent to the Data Provider and she needs to obtain a permission from the Policy Enforcer in her organization to read the results of her query. The Data Provider evaluates the query and also evaluate criticality of the query, where evaluation of sensitiveness is carried out by using clearance rules. In this setting, we present a novel approach, called the DIFF approach, to evaluate security clearance by the Data Provider. Our technique is build on top of relational framework and utilizes pre-evaluated clearances by taking the differences (or deltas) between query results.

本文言語English
ホスト出版物のタイトルDatabase Systems for Advanced Applications - 15th International Conference, DASFAA 2010, Proceedings
ページ299-306
ページ数8
PART 1
DOI
出版ステータスPublished - 2010
イベント15th International Conference on Database Systems for Advanced Applications, DASFAA 2010 - Tsukuba, Japan
継続期間: 2010 4 12010 4 4

出版物シリーズ

名前Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
番号PART 1
5981 LNCS
ISSN(印刷版)0302-9743
ISSN(電子版)1611-3349

Conference

Conference15th International Conference on Database Systems for Advanced Applications, DASFAA 2010
国/地域Japan
CityTsukuba
Period10/4/110/4/4

ASJC Scopus subject areas

  • 理論的コンピュータサイエンス
  • コンピュータ サイエンス(全般)

フィンガープリント

「Efficient database-driven evaluation of security clearance for federated access control of dynamic XML documents」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

引用スタイル