• DocumentCode
    2418366
  • Title

    Translating content-based authorizations for XML documents

  • Author

    Chatvichienchai, Somchai ; Iwaihara, Mizuho ; Kambayashi, Yahiko

  • Author_Institution
    Dept. of Social Informatics, Kyoto Univ., Japan
  • fYear
    2003
  • fDate
    10-12 Dec. 2003
  • Firstpage
    103
  • Lastpage
    112
  • Abstract
    Access control policies of XML documents are often specified based on user roles and data content of the documents. Content-based authorization is crucial for providing fine-grained access control to data in XML document. Since authorization rules (authorizations, for short) use path expressions of XPath for locating data in documents, authorization definition is related to structure of the document. However, the structure of XML documents tends to change by various reasons such as application extension and information exchange between organizations. Therefore, authorizations must be revised whenever they become incompatible with a new structure of the document. As far as we know, no previous work has discussed the problem of transforming content-based authorizations for XML documents by using schema mapping information. We define classes for schema and document transformations that allow transforming authorizations without access to source and target XML documents. We propose an algorithm that computes authorizations of role-based access control (RBAC) model for a target DTD instance from given RBAC authorizations of a source DTD instance and schema mapping information under the specified classes of schema and document transformations while preserving the authorization policy of the source DTD instance.
  • Keywords
    XML; authorisation; tree data structures; trees (mathematics); DTD instance; XML documents; XPath; access control policies; authorization rules; content-based authorizations; data content; data location; document transformations; path expressions; role-based access control; schema mapping information; schema transformations; Access control; Authorization; Automobiles; Computer languages; Costs; Data engineering; Informatics; Information systems; Systems engineering and theory; XML;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Web Information Systems Engineering, 2003. WISE 2003. Proceedings of the Fourth International Conference on
  • Print_ISBN
    0-7695-1999-7
  • Type

    conf

  • DOI
    10.1109/WISE.2003.1254474
  • Filename
    1254474