2004 · 47 citations · 14 references
EngineeringInformation SecuritySoftware EngineeringRole Graph ModelXml SecurityLogical Access ControlAccess MethodAccess ControlManagementSystems EngineeringData IntegrationData ManagementComputer ScienceInformation ManagementXml DatabaseSoftware DesignXml LanguageData SecurityDifferent Access ModesRole-based Access ControlSystem Software
In order to provide a general access control methodology for parts of XML documents, we propose combining role-based access control as found in the Role Graph Model, with a methodology originally designed for object-oriented databases. We give a description of the methodology, showing how different access modes, XPath expressions and roles can be combined, and how propagation of permissions is handled. Given this general approach, a system developer can design a complex authorization model for collections of XML documents.
14
Role-based access control models
Ravi Sandhu, Edward J. Coyne, H.L. Feinstein et al. · Computer · 1996 · 5.8K citations