首页> 外文学位 >Content-Based Access Control.
【24h】

Content-Based Access Control.

机译:基于内容的访问控制。

获取原文
获取原文并翻译 | 示例

摘要

In conventional database, the most popular access control model specifies policies explicitly for each role of every user against each data object manually. Nowadays, in large-scale content-centric data sharing, conventional approaches could be impractical due to exponential explosion of the data growth and the sensitivity of data objects. What's more, conventional database access control policy will not be functional when the semantic content of data is expected to play a role in access decisions. Users are often over-privileged, and ex post facto auditing is enforced to detect misuse of the privileges. Unfortunately, it is usually difficult to reverse the damage, as (large amount of) data has been disclosed already. In this dissertation, we first introduce Content-Based Access Control (CBAC), an innovative access control model for content-centric information sharing. As a complement to conventional access control models, the CBAC model makes access control decisions based on the content similarity between user credentials and data content automatically. In CBAC, each user is allowed by a metarule to access "a subset" of the designated data objects of a content-centric database, while the boundary of the subset is dynamically determined by the textual content of data objects. We then present an enforcement mechanism for CBAC that exploits Oracles Virtual Private Database (VPD) to implement a row-wise access control and to prevent data objects from being abused by unnecessary access admission. To further improve the performance of the proposed approach, we introduce a content-based blocking mechanism to improve the efficiency of CBAC enforcement to further reveal a more relevant part of the data objects comparing with only using the user credentials and data content. We also utilized several tagging mechanisms for more accurate textual content matching for short text snippets (e.g. short VarChar attributes) to extract topics other than pure word occurrences to represent the content of data. In the tagging mechanism, the similarity of content is calculated not purely dependent on the word occurrences but the semantic topics underneath the text content. Experimental results show that CBAC makes accurate access control decisions with a small overhead.
机译:在常规数据库中,最流行的访问控制模型手动针对每个数据对象针对每个用户的每个角色明确指定策略。如今,在大规模的以内容为中心的数据共享中,由于数据增长和数据对象的敏感度呈指数级增长,常规方法可能不切实际。而且,当期望数据的语义内容在访问决策中起作用时,常规的数据库访问控制策略将不起作用。用户通常拥有过多特权,因此,事后进行了审核以检测特权的滥用。不幸的是,由于已经披露了(大量)数据,通常很难逆转这种损害。本文首先介绍基于内容的访问控制(CBAC),它是一种用于以内容为中心的信息共享的创新访问控制模型。作为对传统访问控制模型的补充,CBAC模型基于用户凭据和数据内容之间的内容相似性自动做出访问控制决策。在CBAC中,元规则允许每个用户访问以内容为中心的数据库的指定数据对象的“子集”,而子集的边界由数据对象的文本内容动态确定。然后,我们为CBAC提供了一种强制机制,该机制利用Oracle虚拟专用数据库(VPD)来实现行访问控制,并防止数据对象被不必要的访问许可滥用。为了进一步提高所提出方法的性能,我们引入了一种基于内容的阻止机制,以提高CBAC强制执行的效率,从而与仅使用用户凭据和数据内容相比,可以进一步揭示数据对象中更为相关的部分。我们还利用了几种标记机制来针对短文本片段(例如,短VarChar属性)进行更准确的文本内容匹配,以提取除纯单词出现以外的主题来表示数据内容。在标记机制中,内容相似度的计算不仅仅取决于单词的出现,还取决于文本内容下面的语义主题。实验结果表明,CBAC可以以较小的开销做出准确的访问控制决策。

著录项

  • 作者

    Zeng, Wenrong.;

  • 作者单位

    University of Kansas.;

  • 授予单位 University of Kansas.;
  • 学科 Computer science.
  • 学位 Ph.D.
  • 年度 2015
  • 页码 152 p.
  • 总页数 152
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号