An integrated access control for securely querying and updating XML data
Duong, Maggie and Zhang, Yanchun (2008) An integrated access control for securely querying and updating XML data. Conferences in Research and Practice in Information Technology, 75. pp. 75-83. ISSN 1445-1336
Abstract
Many existing access controls use node filtering or querying rewriting techniques. These techniques require rather time-consuming processes such as parsing, labeling, pruning and/or rewriting queries into safe ones each time a user requests a query or takes an action. In this paper, we propose a fine-grained access control model, named SecureX, which supports read and write privileges. With our novel access control concept, various access types are introduced, including those for determining if a user has the right to change XML structure. Furthermore, SecureX can be integrated well with a dynamic labeling scheme to eliminate repetitive labeling and pruning processes when determining a user view. This brings about advantages of speeding up searching and querying processes. When comparing to a traditional node filtering technique, our integrated access control model takes less processing steps. Experiments have shown effectiveness of our approach.
Item type | Article |
URI | https://vuir.vu.edu.au/id/eprint/3262 |
Official URL | http://crpit.com/confpapers/CRPITV75Duong.pdf |
Subjects | Historical > FOR Classification > 0804 Data Format Historical > FOR Classification > 0806 Information Systems Historical > Faculty/School/Research Centre/Department > School of Engineering and Science |
Keywords | ResPubID16441, access control, XML query, XML update, labeling scheme. |
Citations in Scopus | 7 - View on Scopus |
Download/View statistics | View download statistics for this item |