17th Annual Computer Security Applications Conference (ACSAC'01)
A Component-Based Architecture for Secure Data Publication
New Orleans, Lousiana
December 10-December 14
ISBN: 0-7695-1405-7
We present an approach for controlling access to data publishers in the framework of Web-based information services. The paper presents a model for enforcing access control regulations, an XML core schema and namespace for expressing such regulations, and illustrates the architecture of Access Control Unit (ACU), an autonomous software component based on the proposed model. Besides "standard" authorizations, the ACU supports authorizations based on user profiles and dynamic conditions whose outcome is determined by user actions such as the acceptance of a written agreement and/or payment.
Citation:
P. Bonatti, E. Damiani, S. de Capitani, P. Samarati, "A Component-Based Architecture for Secure Data Publication," acsac, pp.0309, 17th Annual Computer Security Applications Conference (ACSAC'01), 2001