【24h】

Secure XML querying with security views

机译:使用安全视图进行安全的XML查询

获取原文

摘要

The prevalent use of XML highlights the need for a generic, flexible access-control mechanism for XML documents that supports efficient and secure query access, without revealing sensitive information unauthorized users. This paper introduces a novel paradigm for specifying XML security constraints and investigates the enforcement of such constraints during XML query evaluation. Our approach is based on the novel concept of security views, which provide for each user group (a) an XML view consisting of all and only the information that the users are authorized to access, and (b) a view DTD that the XML view conforms to. Security views effectively protect sensitive data from access and potential inferences by unauthorized user, and provide authorized users with necessary schema information to facilitate effective query formulation and optimization. We propose an efficient algorithm for deriving security view definitions from security policies (defined on the original document DTD) for different user groups. We also develop novel algorithms for XPath query rewriting and optimization such that queries over security views can be efficiently answered without materializing the views. Our algorithms transform a query over a security view to an equivalent query over the original document, and effectively prune query nodes by exploiting the structural properties of the document DTD in conjunction with approximate XPath containment tests. Our work is the first to study a flexible, DTD-based access-control model for XML and its implications on the XML query-execution engine. Furthermore, it is among the first efforts for query rewriting and optimization in the presence of general DTDs for a rich a class of XPath queries. An empirical study based on real-life DTDs verifies the effectiveness of our approach.
机译:XML的普遍使用突显了对XML文档的通用灵活访问控制机制的需求,该机制支持有效和安全的查询访问,而又不会泄露未经授权的用户的敏感信息。本文介绍了一种用于指定XML安全约束的新颖范例,并研究了在XML查询评估期间此类约束的实施。我们的方法基于安全视图的新颖概念,该概念为每个用户组提供(a)XML视图,该视图由所有且仅授权用户访问的信息组成,以及(b) XML视图符合的视图DTD。安全视图有效地保护敏感数据免受未经授权的用户的访问和潜在的干扰,并为授权的用户提供必要的架构信息,以促进有效的查询表述和优化。我们提出了一种有效的算法,用于从针对不同用户组的安全策略(在原始文档DTD上定义)中推导安全视图定义。我们还开发了用于XPath查询重写和优化的新颖算法,从而可以在不具体化视图的情况下有效地回答对安全视图的查询。我们的算法将对安全视图的查询转换为对原始文档的等效查询,并通过结合近似的XPath包含测试来利用文档DTD的结构属性,从而有效地修剪查询节点。我们的工作是第一个研究基于XML的灵活,基于DTD的访问控制模型及其对XML查询执行引擎的影响。此外,它是在针对大量XPath查询的通用DTD的情况下进行查询重写和优化的第一批工作。基于实际DTD的实证研究验证了我们方法的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号