文档介绍:1000-9825/2004/15(10)1528 ©2004 Journal of Software 软件学报 ,
∗
面向 XML 文档的细粒度强制访问控制模型
李斓+, 何永忠, 冯登国
(中国科学院软件研究所信息安全国家重点实验室,北京 100080)
A Fine-Grained Mandatory Access Control Model for XML Documents
LI Lan+, HE Yong-Zhong, FENG Deng-Guo
(State Key Laboratory of Information Security, Institute of Software, The Chinese Academy of Sciences, Beijing 100080, China)
+ Corresponding author: Phn: +86-10-62528254 ext 803, E-mail: ******@., .
Received 2003-09-17; Accepted 2003-11-11
Li L, He YZ, Feng DG. A fine-grained mandatory access control model for XML documents. Journal of
Software, 2004,15(10):1528~1537.
/1000-9825/15/
Abstract: Information stored in XML documents should be protected by access control policy. Current access
control models for XML documents are all based on DAC (discretionary access control) or RBAC (role-based
access control). High security system uses MAC (mandatory access control) to secure information in system. XML
document model is extended to include label information in this paper, and some rules that the extended model has
to satisfy with are presented. Fine-grained MAC model for XML documents is described in detail by discussing four
operations on XML documents. The fine-grained MAC model is based on XML schema, and its finest granularity of
access control is element or attribute. The architecture