首页> 外文会议>International conference on web information systems and technologies >Generating XACML Enforcement Policies for Role-Based Access Control of XML Documents
【24h】

Generating XACML Enforcement Policies for Role-Based Access Control of XML Documents

机译:为XML文档的基于角色的访问控制生成XACML强制执行策略

获取原文

摘要

Ensuring the security of electronic data has morphed into one of the most important requirements in domains such as health care, where the extensible Markup Language (XML) has been leveraged via standards such as the Health Level 7's Clinical Document Architecture and the Continuity of Care Record. These standards dictate a need for approaches to secure XML schemas and documents. In this paper, we present a secure information engineering method that is capable of generating extensible Access Control Markup Language (XACML) enforcement policies, defined in a role-based access control model (RBAC), that target XML schemas and their instances, allowing instances to be customized for users depending on their roles. To achieve this goal, we extend the Unified Modeling Language (UML) with two new diagrams: the XML Schema Class Diagram, which defines the structure of an XML document in UML style; and, the XML Role-Slice Diagram, which defines roles and associated privileges at a granular access control level. We utilize a personal health assistant mobile application for medication and chronic disease management to demonstrate the enforcement component of our work.
机译:确保电子数据的安全性变形为域中的域中最重要的要求之一,如保健语言(XML)通过诸如健康级别7的临床文献架构等标准和护理记录的连续性的标准进行了利用。这些标准要求对安全XML模式和文档的方法进行方法。在本文中,我们介绍了一种安全的信息工程方法,能够在基于角色的访问控制模型(RBAC)中定义的可扩展访问控制标记语言(XACML)执行策略,该逻辑XML模式和其实例,允许实例根据其角色为用户自定义。为实现此目标,我们将统一的建模语言(UML)扩展了两个新图:XML模式类图,它定义了UML样式中XML文档的结构;而且,XML角色切片图定义了粒度访问控制级别的角色和关联权限。我们利用个人健康助理移动应用程序进行药物和慢性疾病管理,以展示我们工作的执法部件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号