Regulating access to XML documents

  • Authors:
  • Alban Gabillon;Emmanuel Bruno

  • Affiliations:
  • LIUPPA/CSYSEC. Université de Pau. IUT Antenne de Mont de Marsan. 371 rue du Ruisseau BP 201, 40004 Mont de Marsan Cedex France;SIS - Equipe Informatique. Université de Toulon et du Var. 83957 La Garde, France

  • Venue:
  • Das'01 Proceedings of the fifteenth annual working conference on Database and application security
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, our objective is to define a security model for regulating access to XML documents. Our model offers a security policy with a great expressive power. An XML document is represented by a tree. Nodes of this tree are of different type (element, attribute, text, comment...etc). The smallest protection granularity of our model is the node, that is, authorisation rules granting or denying access to a single node can be defined. The authorisation rules related to a specific XML document are first defined on a separate Authorisation sheet. This Authorisation sheet is then translated into an XSLT sheet. If a user requests access to the XML document then the XSLT processor uses the XSLT sheet to provide the user with a view of the XML document which is compatible with his rights.