...
首页> 外文期刊>Concurrency, practice and experience >Fine-grained filtering to provide access control for data providing services within collaborative environments
【24h】

Fine-grained filtering to provide access control for data providing services within collaborative environments

机译:细粒度过滤可为协作环境中的数据提供服务提供访问控制

获取原文
获取原文并翻译 | 示例
           

摘要

A data providing service (DPS) in service-oriented architecture is tasked only with the retrieval of data thatrnare annotated over a domain ontology. One particular motivating application of DPSs is their use withinrncollaborative environments. An important characteristic for the enterprises of such a collaborativernenvironment is the ability to employ data sharing with one another. A major concern in this situationrnis the protection of each enterprise’s privacy while still permitting data sharing. One potential solutionrnis to provide filtered data through access control. This work describes how to implement access controlrnthrough fine-grained filtering of DPS response messages; it is accomplished using a filtering ontology andrnrelations between the domain ontology of DPS and the proposed filtering ontology. Therefore, enterprisesrncan write enterprise-specific access control policies referencing a common filtering ontology defined withinrna collaborative environment, enabling access control-based data sharing within the environment. This workrnadditionally illustrates the implementation of our general solution to data providing web services, interpretedrnby an eXtensible Access Control Markup Language-based access control framework. The implementationrnis further evaluated in a case study of real world data, provided by a health research institute in London,rnCanada
机译:面向服务的体系结构中的数据提供服务(DPS)仅负责检索在域本体上标注的数据。 DPS的一种特殊激励应用是它们在协作环境中的使用。对于这样一种协作环境的企业来说,一个重要的特征是能够相互使用数据共享。在这种情况下,一个主要问题是在保护每个企业的隐私的同时仍允许数据共享。一种可能的解决方案是通过访问控制提供经过过滤的数据。这项工作描述了如何通过对DPS响应消息进行细粒度过滤来实现访问控制。它是通过使用过滤本体以及DPS的域本体与所提出的过滤本体之间的关系来实现的。因此,企业可以编写企业特定的访问控制策略,并参考在协作环境中定义的通用过滤本体,从而在环境中实现基于访问控制的数据共享。这项工作另外说明了我们的通用解决方案对数据提供Web服务的实现,该解决方案由基于可扩展访问控制标记语言的访问控制框架进行解释。实施者在真实世界数据的案例研究中进一步进行了评估,该案例由加拿大伦敦的一家健康研究所提供

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号