摘要
在信息系统中访问控制是一种基本的安全机制,当多用户系统将XML作为数据存储方式的时候,出现了XML文档的访问控制问题,XML文档具有层次结构,对其访问可以是细粒度的,因此,可以不去访问文件全部信息而限制用户访问文件的部分信息。传统的方法在每次用户请求处理过程中都要将策略文件和数据文件进行比较,因此在数据量比较大的时候就会降低处理效率。将用户请求和策略规则进行分类,并通过比较二者的类型获得授权结果。结果表明,该方法在处理用户访问的过程中减少了访问数据的需要。
Access control is one of the fundamental security mechanisms in information systems.When a multi-user system uses XML documents as data storage,the need of access control to XML documents arises.Due to the hierarchical structure,XML access control is fine-grained in nature.For this criterion,instead of controlling access to the whole XML document,it is possible to limit user access to substructures of the document.authorization process needs to access the data file every time user requests access to data.Evaluating concurrent requests on large data slow down the data access process.In this paper,we use classification of user requests and the user policy,and compare them to get the authorization result.Our experiment shows that the process significantly minimizes the need of data access in the process of evaluating user access.
出处
《皖西学院学报》
2011年第2期27-29,共3页
Journal of West Anhui University
基金
安徽省"质量工程"重点项目(20100873)
皖西学院校级重点项目(2010LWA006)
关键词
XML
访问控制
授权
XML
access control
authorization