首页> 外文会议>International Workshops on Foundations and Applications of Self* Systems >An incremental approach to data integration in presence of access control policies
【24h】

An incremental approach to data integration in presence of access control policies

机译:在访问控制策略存在下的数据集成递增方法

获取原文

摘要

In this paper, we describe an approach for data integration that takes into account access control policies. In a data integration system, a mediator is defined as unique entry point providing transparent access to distributed, autonomous and heterogeneous data sources. In such an architecture (see Figure 1), security issue and access control in particular is considered as challenging tasks. Indeed, every source, designed independently from the others, uses its own access control policy to protect their data. The central challenge identified in this context is: How to synthesize a global policy at the mediator level that complies with the policies of the sources? Complying with the sources' policies means that an unauthorized access at the source level should also be unauthorized at the mediator level. Also, the policy of the mediator should ensure data protection against indirect accesses. An indirect access may take place when one could infer sensitive information from non-sensitive one by using semantic constraints. We propose a methodology that can help to synthesize a global policy with a global schema and to detect security breaches by reasoning about semantic constraints.
机译:在本文中,我们描述了一种用于考虑访问控制策略的数据集成方法。在数据集成系统中,中介被定义为唯一的入口点,提供对分布式,自主和异构数据源的透明访问。在这样的架构中(参见图1),特别是安全问题和访问控制被认为是具有挑战性的任务。实际上,每个源都独立地从其他来源设计,使用自己的访问控制策略来保护他们的数据。在这方面确定的中央挑战是:如何在符合来源政策的调解员水平上综合全球政策?遵守来源的政策意味着在源级别的未经授权访问也应在调解员级别未经授权。此外,调解员的策略应确保对间接访问的数据保护。当一个人可以通过使用语义约束来从非敏感性敏感信息推断敏感信息时,可以进行间接访问。我们提出了一种可以帮助综合全球架构的全球策略的方法,并通过推理语义限制来检测安全漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号