Relational access control with bivalent permissions in a social Web/collaboration architecture

Collaborative Technologies and Systems(2013)

引用 1|浏览9
暂无评分
摘要
We describe an access control model that has been implemented in the web content management framework “Deme” (which rhymes with “team”). Access control in Deme is an example of what we call “bivalent relation object access control” (BROAC). This model builds on recent work by Giunchiglia et al. on relation-based access control (RelBAC), as well as other work on relational, flexible, fine-grained, and XML access control models. We describe Deme's architecture and review access control models, motivating our approach. BROAC allows for both positive and negative permissions, which may conflict with each other. We argue for the usefulness of defining access control rules as objects in the target database, and for the necessity of resolving permission conflicts in a social Web/collaboration architecture. After describing how Deme access control works, including the precedence relations between different permission types in Deme, we provide several examples of realistic scenarios in which permission conflicts arise, and show how Deme resolves them. Initial performance tests indicate that permission checking scales linearly in time on a practical Deme website.
更多
查看译文
关键词
Internet,Web sites,XML,authorisation,groupware,software architecture,Deme Web site,Deme architecture,Web content management framework,XML access control,bivalent permissions,bivalent relation object access control,collaboration architecture,permission checking,relational access control,social Web,access control,collaborative work,content management,permissions,social factors,social web applications
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要