Static analysis of XML security views and query rewriting

Static analysis of XML security views and query rewriting
复制标题

XML安全视图的静态分析和查询重写

DOI:
10.1016/j.ic.2014.07.003
复制
发表时间:
2014
期刊:
Inf. Comput.
影响因子:
--
通讯作者:
S. Tison
S. Tison
中科院分区:
--
文献类型:
--
作者:
Benoît Groz;Slawomir Staworko;Anne;Yves Roos;S. Tison

文献摘要

被引文献

相似文献

在本文中,我们重新审视了基于视图的XML安全框架,而没有对查询类、dtd类和用于定义视图的注释类型施加任何先前考虑过的限制。首先,我们研究用于定义查询和视图的类是正则XPath和MSO时的视图查询重写。接下来,我们研究安全访问规范(SAS)的静态分析问题:我们引入了一类新的间隔有界的SAS,并从安全的角度定义了三种不同的方式来比较视图(即查询)。我们对决定这三种比较的复杂性进行了系统的研究:当XML文档的深度是有界的,当文档可能具有任意深度但定义视图的查询受到限制以保证间隔有界的属性,以及在一般设置中对查询和文档没有限制。
In this paper, we revisit the view based security framework for XML without imposing any of the previously considered restrictions on the class of queries, the class of DTDs, and the type of annotations used to define the view. First, we studyquery rewritingwith views when the classes used to define queries and views are Regular XPath and MSO. Next, we investigate problems ofstatic analysisof security access specifications (SAS): we introduce the novel class ofinterval-boundedSAS and we define three different manners to compare views (i.e. queries) from a security point of view. We provide a systematic study of the complexity for deciding these three comparisons, when the depth of the XML documents is bounded, when the document may have an arbitrary depth but the queries defining the views are restricted to guarantee the interval-bounded property, and in the general setting without restriction on queries and document.