RDF Access Control
 
     
 
 
 
 

An Authorization Framework for RDF ontology data

Semantic Web research aims to support intelligent data integration from heterogeneous sources and improve collaboration among web applications and services. The basic building blocks of the envisioned Semantic Web are the Extensible Markup Language (XML), Resource Description Framework (RDF), and OWL. Where XML provides a mechanism for syntactic data storage and interchange, RDF provides semantic meaning to this data. However, the security impact of the Semantic Web has not been studied sufficiently. Some of the research topics currently addressed include Web trust, XML access control models, and distributed authentications.

This research work proposes an Access Control Framework for the RDF data. Although there are several proposed access control models for data stored in XML, these models are based on XML syntax only and incapable of incorporating data semantics. Due to syntactic variances of the XML representations corresponding to the same data, access control policies developed for one representation are not applicable to a different representation. Further, RDF does have entailment, which can lead to unwanted data inferences and cause data leaks. We develop an Access Control Language that is based on the meaning (semantics) of the data rather than its syntactic representation. Our model secures RDF data by assigning Multi Level security classifications to it and also preserves the flexibility provided in RDF model. It also provides means to secure the data from illegal inferences.



Publications:

RAF (RDF Authorization Framework) implementation (version 0.1)
  • Source code available on request. Contact us at .
 
 

 

 

This webpage is based upon work supported by the National Science Foundation under Grant No. IIS-0237782.
Any opinions, findings and conclusions or recommendations expressed in this material are those of the author(s) and do not necessarily reflect the views of the National Science Foundation (NSF).
This page is maintained by CIAE Webmaster. All contents copyright ©The Board of Trustees of the University of South Carolina.
Last Modified : Sunday, 07-Sep-2008 13:55:31 EDT