The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

Protection and administration of XML data sources

Download

Download PDF Document
PDF

Author

Elisa Bertino

Entry type

article

Abstract

EXtensible Markup Language (XML) security has become a relevant research topic due to the widespread use of XML as the language for information interchange and document definition over the Web. In this context, developing an access control mechanism in terms of XML is an important step for Web information security. In this paper, we present the protection and administration facilities of Author-Image , a Java-based system for discretionary access control to XML documents. Relevant features of Author-Image are both a set-oriented and a document-oriented credential-based document protection, a differentiated protection of document/document type contents through the support of multi-granularity protection objects and positive/negative authorizations, and the support for different access control strategies. In this paper, we focus on the strategies we have developed for enforcing access control. Additionally, we provide a description of the environment we have developed to help the Security Officer in performing administrative activities related to both security policy and subject credential management.

Download

PDF

Date

2002 – 12

Journal

Data & Knowledge Engineering

Key alpha

Bertino

Pages

237-260

Publisher

Elsevier Science

Volume

43

Affiliation

Purdue University

Publication Date

2002-12-01

BibTex-formatted data

To refer to this entry, you may select and copy the text below and paste it into your BibTex document. Note that the text may not contain all macros that BibTex supports.