首页> 外文学位 >Security on the Web: A semantic-aware authorization framework for secure data sharing.
【24h】

Security on the Web: A semantic-aware authorization framework for secure data sharing.

机译:Web上的安全性:一种用于安全数据共享的语义感知授权框架。

获取原文
获取原文并翻译 | 示例

摘要

This PhD dissertation proposes a Semantic-Aware Authorization Framework to address some of the problems encountered in sharing semi-structured data securely. The proposed framework ensures the preservation of authorization permissions on data even if the structure of the data is changed during the data exchange. This framework supports data sharing in distributed and heterogeneous environments by providing syntax independent authorization capabilities for eXtensible Markup Language (XML), the most widely used standard for data format and exchange. Most of the security standards available for XML data security use the syntax and structure of the XML data to provide different security services. In this research work, I propose an approach to remove the dependence of security on data syntax and make use of data and application semantics to secure XML documents. In particular, I have developed an Access Control framework for XML that expresses authorization requirements on data semantics. I define a XML to ontology mappings to associate XML data documents with their semantics.;First, I show how to map an XML data document to a corresponding ER model. Security requirements are expressed onto ER conceptual models. I use these mappings to derive the security policies for XML document from authorizations expressed on the ER model. This architecture has limitations in the wake of current distributed nature of the web and enterprise application scenarios. Using ontologies enables several advantages over ER model usage such as easier data model integration, relationship modeling, extensibility, and open sharing. But this entails the need for an access control model to secure metadata RDF.;Hence using semantics for securing XML data presents two requirements, (1) Developing authorization framework for metadata represented in RDF format, (2) Establishing mappings between the XML data and its semantics, presented by RDF ontology, to propagate the RDF authorizations to XML data. So the proposed framework, in addition to providing a uniform access control model for XML data, also provides an authorization model for RDF ontological data. Formal properties of the proposed model such as completeness, consistency, and default policy for both RDF and mapped XML data are also developed.
机译:本博士论文提出了一种语义感知授权框架,以解决安全共享半结构化数据时遇到的一些问题。所提出的框架确保即使在数据交换期间数据的结构发生更改时,也可以保留对数据的授权权限。该框架通过为可扩展标记语言(XML)提供语法独立的授权功能来支持分布式和异构环境中的数据共享,可扩展标记语言(XML)是使用最广泛的数据格式和交换标准。可用于XML数据安全的大多数安全标准都使用XML数据的语法和结构来提供不同的安全服务。在这项研究工作中,我提出了一种方法来消除安全性对数据语法的依赖性,并利用数据和应用程序语义来保护XML文档的安全。特别是,我为XML开发了访问控制框架,该框架表达了对数据语义的授权要求。我定义了XML到本体的映射,以将XML数据文档与其语义相关联。首先,我展示了如何将XML数据文档映射到相应的ER模型。安全要求在ER概念模型中表达。我使用这些映射从ER模型上表达的授权中得出XML文档的安全策略。在当前Web和企业应用程序场景的分布式特性之后,此体系结构具有局限性。与ER模型的使用相比,使用本体具有多个优势,例如,更轻松的数据模型集成,关系建模,可扩展性和开放共享。但是,这需要使用访问控制模型来保护元数据RDF。因此,使用语义保护XML数据存在两个要求:(1)开发以RDF格式表示的元数据的授权框架;(2)在XML数据和XML之间建立映射。它的语义(由RDF本体提供)将RDF授权传播到XML数据。因此,提出的框架除了为XML数据提供统一的访问控制模型外,还为RDF本体数据提供了授权模型。还开发了所提议模型的形式属性,例如RDF和映射的XML数据的完整性,一致性和默认策略。

著录项

  • 作者

    Jain, Amit.;

  • 作者单位

    University of South Carolina.;

  • 授予单位 University of South Carolina.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2008
  • 页码 124 p.
  • 总页数 124
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号