skip to main content
10.1145/2393216.2393285acmotherconferencesArticle/Chapter ViewAbstractPublication PagesccseitConference Proceedingsconference-collections
research-article

Storing XML rules in relational storage of XML DTD

Published:26 October 2012Publication History

ABSTRACT

very few research works have been done on XML security over relational databases despite that XML became the de facto standard for the data representation and exchange on the internet and a lot of XML documents are stored in RDBMS. In [14], the author proposed an access control model for schema-based storage of XML documents in relational storage and translating XML access control rules to relational access control rules. However, the proposed algorithms had performance drawbacks. In this paper, we will use the same access control model of [14] and try to overcome the drawbacks of [14] by proposing an efficient technique to store the XML access control rules in a relational storage of XML DTD. The mapping of the XML DTD to relational schema is proposed in [7]. We also propose an algorithm to translate XPath queries to SQL queries based on the mapping algorithm in [7].

References

  1. R. Abassi, F. Jacquemard, M. Rusinowitch, and S. G. E. Fatmi. XML Access Control:from XACML to Annotated Schemas. In Proceedings of the 2nd International Conference on Communications and Networking (ComNet), pages 1--8, 2010.Google ScholarGoogle Scholar
  2. E. Bertino and E. Ferrari. Secure and Selective Dissemination of XML Documents. ACM Transactions on Information and System Security (TISSEC), 5(3):290-- 331, Aug., 2002. Google ScholarGoogle ScholarDigital LibraryDigital Library
  3. S. Chang, A. Chebotko, S. Lu, and F. Fotouhi. Graph Matching Based Authorization Model for Effiient Secure XML Querying. In Proceedings of the AINA Workshops, pages 473--478, 2007. Google ScholarGoogle ScholarDigital LibraryDigital Library
  4. E. Damiani, S. Vimercati, S. Paraboschi, and P. Samarati. Design and Implementation of an Access Control Processor for XML Documents. Computer Networks, 33(6):59--71, 2000. Google ScholarGoogle ScholarDigital LibraryDigital Library
  5. E. Damiani, S. Vimercati, S. Paraboschi, and P. Samarati. Securing XML documents. In Proceedings of the International Conference on Extending Databas Technology, pages 121--135, 2000. Google ScholarGoogle ScholarDigital LibraryDigital Library
  6. E. Damiani, S. Vimercati, S. Paraboschi, and P. Samarati. A Fine-Grained Access Control System for XML Documents. ACM Transactions on Information and System Security (TISSEC), 5(2):169--202, May, 2000. Google ScholarGoogle ScholarDigital LibraryDigital Library
  7. A. A. A. El-Aziz and A. Kannan. Mapping XML DTDs to Relational Schemas. In Proceedings of the 2nd International Conference on Computer Communication and Informatics (ICCCI), pages 1--7, 10--12 Jan., 2012.Google ScholarGoogle Scholar
  8. W. Fan, C. Chan, and M. Garofalakis. Secure XML quering with security views. In Proceedings of SIGMOD 2004, pages 587--598, 2004. Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. A. Gabillon and E. Bruno. Regulating Access to XML Documents. In Proceedings of the Working Conference on Database and Application Security, July, 2001. Google ScholarGoogle ScholarDigital LibraryDigital Library
  10. D. Lee, W. Lee, and P. Liu. Supporting XML Security Models using Relational Databases. A Vision. Lecture Note In Computer Science, Springer-Verlag Berlin Heidelberg, pages 267--281, Sep., 2003.Google ScholarGoogle Scholar
  11. B. Luo, D. Lee, and P. Liu. Pragmatic XML Access Control using Off-the-shelf RDBMS. In Proceedings of the 12th European Symposium on Research in Computer Security (ESORICS), pages 55--71, 24--26 Sep., 2007. Google ScholarGoogle ScholarDigital LibraryDigital Library
  12. S. Mohan, A. Sengupta, Y. Wu, and J. Klinginsmith. Access Control for XML-A Dynamic Query Rewrinting Approach. In Proceedings of the 14th ACM international conference on Information and knowledge management, 2005. Google ScholarGoogle ScholarDigital LibraryDigital Library
  13. M. Murata, A. Tozawa, and M. Kudo. XML Access Control using Static Analysis. In Proceedings of the 10th ACM conference on Computer and communications security, pages 73--84, Oct., 2003. Google ScholarGoogle ScholarDigital LibraryDigital Library
  14. J. Patel and M. Atay. An Efficient Access Control Model for Schema-Based Relational Storage of XML Documents. In Proceedings of the 49th Annual ACM Southeast Regional Conference, pages 97--102, 24--24 March, 2011. Google ScholarGoogle ScholarDigital LibraryDigital Library
  15. K. L. Tan, M. L. Lee, and Y. Wang. Access Control of XML Documents in Relational Database Systems. In Proceedings of the International Conference on Internet Computing (IC), pages 185--191, 2001.Google ScholarGoogle Scholar

Index Terms

  1. Storing XML rules in relational storage of XML DTD

    Recommendations

    Comments

    Login options

    Check if you have access through your login credentials or your institution to get full access on this article.

    Sign in
    • Published in

      cover image ACM Other conferences
      CCSEIT '12: Proceedings of the Second International Conference on Computational Science, Engineering and Information Technology
      October 2012
      800 pages
      ISBN:9781450313100
      DOI:10.1145/2393216

      Copyright © 2012 ACM

      Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      • Published: 26 October 2012

      Permissions

      Request permissions about this article.

      Request Permissions

      Check for updates

      Qualifiers

      • research-article

    PDF Format

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader