A formal access control model for XML databases

  • Authors:
  • Alban Gabillon

  • Affiliations:
  • IUT de Mont de Marsan, LIUPPA/CSySEC, Université de Pau et des Pays de l’Adour, Mont de Marsan, France

  • Venue:
  • SDM'05 Proceedings of the Second VDLB international conference on Secure Data Management
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, we first define a logical theory representing an XML database supporting XPath as query language and XUpdate as modification language. We then extend our theory with predicates allowing us to specify the security policy protecting the database. The security policy includes rules addressing the read and write privileges. We propose axioms to derive the database view each user is permitted to see. We also propose axioms to derive the new database content after an update.