首页> 外文会议>International conference on database and expert systems applications >An XML-Based Policy Model for Access Control in Web Applications
【24h】

An XML-Based Policy Model for Access Control in Web Applications

机译:Web应用程序中基于XML的访问控制策略模型

获取原文

摘要

Organizational Information Systems (IS) collect, store, and manage personal and business data. Due to regulation laws and to protect the privacy of users, clients, and business partners, these data must be kept private. This paper proposes a model and a mechanism that allows defining access control policies based on the user profile, the time period, the mode and the location from where data can be accessed. The proposed policy model is simple enough to be used by a business manager, yet it has the flexibility to define complex restrictions. At runtime, a protection layer monitors data accesses and enforces existing policies. A prototype tool was implemented to run an experimental evaluation, which showed that the tool is able to enforce access control with minimal performance impact, while assuring scalability both in terms of the number of users and the number of policies.
机译:组织信息系统(IS)收集,存储和管理个人和企业数据。根据法规法规并为了保护用户,客户和业务合作伙伴的隐私,必须将这些数据保密。本文提出了一种模型和一种机制,该模型和机制允许基于用户配置文件,时间段,模式和可访问数据的位置来定义访问控制策略。提议的策略模型非常简单,可以被业务经理使用,但是它具有定义复杂限制的灵活性。在运行时,保护层监视数据访问并强制执行现有策略。实施了一个原型工具来进行实验评估,结果表明该工具能够以最小的性能影响实施访问控制,同时在用户数量和策略数量上确保可伸缩性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号