On specifying security policies for web documents with an XML-based language

  • Authors:
  • Elisa Bertino;Silvana Castano;Elena Ferrari

  • Affiliations:
  • Univ. Degli Studi di Milano, Milan, Italy;Univ. Degli Studi di Milano, Milan, Italy;Univ. Degli Studi di Milano, Milan, Italy

  • Venue:
  • SACMAT '01 Proceedings of the sixth ACM symposium on Access control models and technologies
  • Year:
  • 2001

Quantified Score

Hi-index 0.01

Visualization

Abstract

The rapid growth of the Web and the ease with which data can be accessed facilitate the distribution and sharing of information. Information dissemination often takes the form of documents that are made available at Web servers, or that are actively broadcasted by Web servers to interested clients. In this paper, we present an XML-compliant formalism for specifying security-related information for Web document protection. In particular, we introduceX-Sec, an XML-based language for specifying subject credentials and security policies and for organizing them into subject profiles and policy bases, respectively. The language is complemented by a set of subscription-based schemes for accessing distributed Web documents, which rely on defined XML subject profiles and XML policy bases.