An efficient yet secure XML access control enforcement by safe and correct query modification

  • Authors:
  • Changwoo Byun;Seog Park

  • Affiliations:
  • Department of Computer Science, Sogang University, Seoul, South Korea;Department of Computer Science, Sogang University, Seoul, South Korea

  • Venue:
  • DEXA'06 Proceedings of the 17th international conference on Database and Expert Systems Applications
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

This work is a proposal for an efficient yet secure XML access control enforcement which has been specifically designed to support fine-grained security policy. Based on metadata in the DTD, we propose the SQ-Filter which is a pre-processing method that checks on necessary access control rules, and rewrites a user's query by extending/eliminating query tree nodes, and by injecting operators that combine a set of nodes from the user's query point of view. The scheme has several advantages over other suggested schemes. These include small execution time overhead, and safe and correct query modification. The experimental results clearly demonstrate the efficiency of the approach.