In order to provide a general access control methodology for parts of XML documents, we propose combining rolebased access control as found in the Role Graph Model, with a methodology originally designed for object-oriented databases. We give a description of the methodology, showing how different access modes, XPath expressions and roles can be combined, and how propagation of permissions is handled. Given this general approach, a system developer can design a complex authorization model for collections of XML documents. Categories and Subject Descriptors D.4.6 [Software]: Security and Protection—Access controls; K.6.5 [Computing Millieux]: Security and Protection General Terms Algorithms, Security Keywords role-based access control, XML databases
Jingzhu Wang, Sylvia L. Osborn