首页> 外文会议>International conference on web information systems and technologies >Generating XACML Enforcement Policies for Role-Based Access Control of XML Documents
【24h】

Generating XACML Enforcement Policies for Role-Based Access Control of XML Documents

机译:生成XACML强制策略以实现基于角色的XML文档访问控制

获取原文

摘要

Ensuring the security of electronic data has morphed into one of the most important requirements in domains such as health care, where the extensible Markup Language (XML) has been leveraged via standards such as the Health Level 7's Clinical Document Architecture and the Continuity of Care Record. These standards dictate a need for approaches to secure XML schemas and documents. In this paper, we present a secure information engineering method that is capable of generating extensible Access Control Markup Language (XACML) enforcement policies, defined in a role-based access control model (RBAC), that target XML schemas and their instances, allowing instances to be customized for users depending on their roles. To achieve this goal, we extend the Unified Modeling Language (UML) with two new diagrams: the XML Schema Class Diagram, which defines the structure of an XML document in UML style; and, the XML Role-Slice Diagram, which defines roles and associated privileges at a granular access control level. We utilize a personal health assistant mobile application for medication and chronic disease management to demonstrate the enforcement component of our work.
机译:确保电子数据的安全性已成为医疗保健等领域中最重要的要求之一,在该领域中,可扩展标记语言(XML)已通过诸如Health Level 7的临床文档架构和护理记录连续性之类的标准加以利用。这些标准表明需要一种方法来保护XML模式和文档的安全。在本文中,我们提出了一种安全的信息工程方法,该方法能够生成可扩展的访问控制标记语言(XACML)实施策略,该策略在基于角色的访问控制模型(RBAC)中定义,以XML模式及其实例为目标,从而允许实例根据用户角色进行定制。为了实现此目标,我们用两个新图扩展了统一建模语言(UML):XML Schema Class Diagram,它以UML样式定义XML文档的结构; XML角色切片图,它在粒度访问控制级别定义了角色和相关的特权。我们将个人健康助手移动应用程序用于药物和慢性病管理,以演示我们工作的执行组成部分。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号