DocumentCode :
407676
Title :
Securing XML document sources and their distribution
Author :
Zhang, Junqi ; Varadharajan, Vijay ; Mu, Yi
Author_Institution :
Dept. of Comput., Macquarie Univ., Sydney, NSW, Australia
Volume :
1
fYear :
2004
fDate :
2004
Firstpage :
562
Abstract :
XML has been becoming popular for data store, document representation and exchange over the Web. Security mechanisms for the protection of XML document sources and their distribution are essential. Author-X is a Java based system specifically conceived for the protection of XML documents. It supports a range of protection granularity levels and subject credentials, but also supports push distribution for documents broadcast. However, the proposed system has certain disadvantages in terms of both security and dynamic key management. For example, a sender has to distribute the secret keys to all correspondent users for different XML documents. Also, if one of the users leave or a credential is changed, then the sender has to re-encrypt all related documents and redistribute the secret keys to all correspondent users. In this paper, we present a scheme for securing XML documents and their distribution. Our scheme has several advantages over Author-X such as: (a) one user needs only one private key; (b) even when the user leaves or a credential is changed, all the other users will be unaffected; (c) there is no need to establish a secure channel for key distribution; and (d) there is no need for checking the XML documents for access control policies applied. These make the security model more efficient and robust as well as simplifying the programming and the generation of the encrypted document base.
Keywords :
Internet; Java; XML; public key cryptography; telecommunication security; Author-X; Java based system; World Wide Web; XML document distribution; XML document sources; XML documents protection; access control policies; correspondent users; data storage; document exchange; document representation; documents broadcast; dynamic key management; encrypted document base; encryption; private key; protection granularity levels; push distribution; secret key distribution; secure channel; security mechanisms; security model; subject credentials; XML;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Advanced Information Networking and Applications, 2004. AINA 2004. 18th International Conference on
Print_ISBN :
0-7695-2051-0
Type :
conf
DOI :
10.1109/AINA.2004.1283969
Filename :
1283969
Link To Document :
بازگشت