首页> 外文会议>ACM symposium on access control models and technologies >Access Control for RDF Graphs using Abstract Models
【24h】

Access Control for RDF Graphs using Abstract Models

机译:使用抽象模型访问RDF图表的控制控制

获取原文

摘要

The Resource Description Framework (RDF") has become the defacto standard for representing information in the Semantic Web. Given the increasing amount of sensitive RDF data available on the Web, it becomes increasingly critical to guarantee secure access to this content. In this paper we advocate the use of an abstract access control model to ensure the selective exposure of RDF information. The model is defined by a set of abstract operators and tokens, tokens are used to label RDF triples with access information. Abstract operators model RDF Schema inference rules and propagation of labels along the RDF Schema (RDFS) class and property hierarchies. In this way, the access label of a triple is a complex expression that involves the labels of the triples and the operators applied to obtain said label. Different applications can then adopt different concrete access policies that encode an assignment of the abstract tokens and operators to concrete (specific) values. Following this approach, changes in the interpretation of abstract tokens and operators can be easily implemented resulting in a very flexible mechanism that allows one to easily experiment with different concrete access policies (defined per context or user). To demonstrate the feasibility of the approach, we implemented our ideas on top of the MonetDB and Post-greSQL open source database systems. We conducted an initial set of experiments which showed that the overhead for using abstract expressions is roughly linear to the number of triples considered; performance is also affected by the characteristics of the dataset, such as the size and depth of class and property hierarchies as well a,s the considered concrete policy.
机译:资源描述框架(RDF“)已成为代表语义Web中的信息的Defacto标准。考虑到Web上可用的敏感RDF数据的增加,因此保证安全访问此内容变得越来越关键。在本文中,我们提倡使用抽象访问控制模型,以确保RDF信息的选择性曝光。该模型由一组抽象运算符和令牌定义,令牌用于标记具有访问信息的RDF三倍。抽象运算符模型RDF架构推理规则和沿RDF架构(RDFS)类和属性层次结构的标签传播。以这种方式,三重访问标签是一种复杂的表达式,涉及三元组的标签和应用于获得所述标签的操作员。然后可以采用不同的应用程序将抽象令牌和运营商的分配分配给混凝土(特定)值的不同具体访问策略。以下OACH,可以轻松实现抽象令牌和运营商解释的变化,从而实现了一个非常灵活的机制,允许人们轻松地实验不同的具体访问策略(定义每个上下文或用户)。为了展示方法的可行性,我们在MonetDB和后GRESQL开源数据库系统的顶部实施了我们的想法。我们进行了一组初始实验,表明使用抽象表达的开销是大致线性的,以考虑的三元组;性能也受到数据集的特征的影响,例如类和属性层次结构的大小和深度,也是所考虑的具体政策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号