Generalized XML security views

G. Kuper, F. Massacci, N. Rassadko

Research output: Chapter in Book / Report / Conference proceedingConference contributionAcademicpeer-review

Abstract

We investigate a generalization of the notion of XML security view introduced by Stoica and Farkas [17] and later refined by Fan et al. [8]. The model consists of access control policies specified over DTDs with XPath expression for data-dependent access control policies. We provide the notion of security views for characterizing information accessible to authorized users. This is a transformed (sanitized) DTD schema that can be used by users for query formulation and optimization. Then we show an algorithm to materialize "authorized" version of the document from the view and an algorithm to construct the view from an access control specification. We also propose a number of generalizations for security policies 1. Copyright 2005 ACM.
Original languageEnglish
Title of host publicationSACMAT 2005: Proceedings of 10th ACM Symposium on Access Control Models and Technologies
Pages77-84
DOIs
Publication statusPublished - 2005
Externally publishedYes
EventSACMAT 2005: Proceedings of 10th ACM Symposium on Access Control Models and Technologies - , Sweden
Duration: 1 Jun 20053 Jun 2005

Publication series

NameProceedings of ACM Symposium on Access Control Models and Technologies, SACMAT

Conference

ConferenceSACMAT 2005: Proceedings of 10th ACM Symposium on Access Control Models and Technologies
Country/TerritorySweden
Period1/06/053/06/05

Fingerprint

Dive into the research topics of 'Generalized XML security views'. Together they form a unique fingerprint.

Cite this