On Securely Manipulating XML Data - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2012

On Securely Manipulating XML Data

Résumé

Over the past years several works have proposed access control models for XML data where only read-access rights over non-recursive DTDs are considered. A small number of works have studied the access rights for updates. In this paper, we present a general model for specifying access control on XML data in the presence of the update operations of W3C XQuery Update Facility. Our approach for enforcing such update spec- ification is based on the notion of query rewriting. A major issue is that query rewriting for recursive DTDs is still an open problem. We show that this limitation can be avoided using only the expressive power of the standard XPath, and we propose a linear algorithm to rewrite each update operation defined over an arbitrary DTD (recursive or not) into a safe one in order to be evaluated only over the XML data which can be updated by the user. This paper represents the first effort for securely XML updating in the presence of arbitrary DTDs (recursive or not) and a rich fragment of XPath. Finally, we study the interaction between read and update access rights to preserve the confidentiality and integrity of XML data.
Fichier non déposé

Dates et versions

hal-00759898 , version 1 (03-12-2012)

Identifiants

  • HAL Id : hal-00759898 , version 1

Citer

Houari Mahfoud, Abdessamad Imine. On Securely Manipulating XML Data. Conférence des Bases de Données Avancées (BDA 2012), Oct 2012, Clermont-Ferrand, France. ⟨hal-00759898⟩
120 Consultations
0 Téléchargements

Partager

Gmail Facebook X LinkedIn More