Detecting information leakage in updating XML documents of fine-grained access control

  • Authors:
  • Somchai Chatvichienchai;Mizuho Iwaihara

  • Affiliations:
  • Dept. of InfoMedia, Siebold University of Nagasaki, Nagasaki, Japan;Dept. of Social Informatics, Graduate School of Informatics, Kyoto University, Kyoto, Japan

  • Venue:
  • DEXA'06 Proceedings of the 17th international conference on Database and Expert Systems Applications
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

To provide fine-grained access control to data in an XML document, XML access control policy is defined based on the contents and structure of the document. In this paper, we discuss confidential information leakage problem caused by unsecure-update that modifies contents or structures of the document referred by the access control policy. In order to solve this problem, we propose an algorithm that computes update constraints of a user on some data in the document under access control policy of the user. We also propose an algorithm that decides whether a given update request of a user against an XML document is an unsecure-update under the user's access control policy.