XML-BB: a model to handle relationships protection in XML documents

  • Authors:
  • Frédéric Cuppens;Nora Cuppens-Boulahia;Thierry Sans

  • Affiliations:
  • GET, ENST Bretagne, Cesson-Sévigné Cedex, France;GET, ENST Bretagne, Cesson-Sévigné Cedex, France;GET, ENST Bretagne, Cesson-Sévigné Cedex, France

  • Venue:
  • KES'07/WIRN'07 Proceedings of the 11th international conference, KES 2007 and XVII Italian workshop on neural networks conference on Knowledge-based intelligent information and engineering systems: Part III
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Since XML became the core meta language for many data formats, we need a fine-grained access control model for XML to protect sensitive information carried by XML elements or by relationships between these elements. Several models have already been suggested, but we claim that none of them is sufficiently expressive to properly express some basic security requirements, especially those related to entity relationships protection. To cope with these limitations, we suggest to structure the access control policy using the new concept of block. This is used to hide relationships between nodes selected in different blocks. It provides means to specify confidentiality restriction associated with some relationships. An access control model, called XML-BB (XML Block Based Access Control), that includes this concept of block is presented and the implementation of this model is described.