Font Size: a A A

Research On Authorization And Access Control For XML

Posted on:2008-03-17Degree:MasterType:Thesis
Country:ChinaCandidate:X Q ZhouFull Text:PDF
GTID:2178360272968192Subject:Information security
Abstract/Summary:PDF Full Text Request
XML is short for Extensible Markup Language which can create its own tags. Recently, XML is widely used in all fields. As its standardization develops, its future will be brighter. As XML has become the actual standard for the data coding, it will replace the traditional data format. So how to secure the XML documents is becoming an important issue in system security. For control access to the data resource, DAC, MAC, and RBAC have been developed. RBAC is often used to authorize and control the access to XML as it is a format of data.We can use the existing research results when using the traditional RBAC. But the traditional RBAC has not considered the features of XML. Without considering the features of XML, it is difficult to develop efficient system for XML authorization and access control. Especially in the Web environment where user has great demand on the processing speed, the traditional access control systems are not enough. So under condition of system security it is necessary to improve the processing speed by considering the features of XML. The main feature of XML is semi-constructor, in which the structure of an XML document is a tree. Each node in the tree are information items, they are associated but separate to a degree. And different elements have different secure needs. So we have to constitute different secure policies for different elements which are called fine-grained.Using the fine-grained model of authorization and access control, different authorization rules can be constituted for different elements. Each authorization has three attributes which are level, propagation and strength. So there are eight kinds of authorization as every attribute has two possible values.
Keywords/Search Tags:XML, XML Schema, Tree of Authorization Rules, Priority
PDF Full Text Request
Related items