I Own, I Provide, I Decide: Generalized User-Centric Access Control Framework for Web Applications

نویسندگان

  • Kapil Singh
  • Ikpeme Erete
  • Wenke Lee
چکیده

With the rapid growth of Web 2.0 technologies, users are contributing more and more content on the Internet, in the form of user profiles, blogs, reviews, etc. With this increased sharing comes a pressing need for access control policies and mechanisms to protect the users’ privacy. Access control has remained largely centralized and under the control of the web applications hosted on their servers. Moreover, most web applications either provide no or very primitive and limited access control. We argue that the owner of any piece of data on the web should be able to decide how to control access to this data. This argument should hold not only for the web applications contributing data, but also for the contributing users. In other words, users should be able to choose their own access control models to control the sharing of their data independent of the underlying applications of their data. In this work, we present a novel framework, called xAccess, for providing generic access control that empowers users to control how they want their data to be accessed. Such a control could be in the form of user-defined access categories, or in the form of new access control models built on top of our framework. On one hand, xAccess enables individual users to use a single unified access control across multiple web applications; and on the other hand, it allows an application to support different access control models deployed by its users with a single model abstraction. We demonstrate the viability of our design by means of a platform prototype. The usability of the platform is further evaluated by developing sample applications using the xAccess APIs. Our results show that our model incurs minimum overhead in enforcing the generic access control and requires negligible changes to the application code for deployment.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Developing a Recommendation Framework for Tourist by Mining Geo-tag Photos (Case Study Tehran District 6)

With the increasing popularity of sharing media on social networks and facilitating access to location technologies, such as Global Positioning System (GPS), people are more interested to share their own photos and videos. The world wide web users are no longer the sole consumer but they are producers of information also, hence a wealth of information are available on web 2.0 applications. The ...

متن کامل

Approximation of a generalized Euler-Lagrange type additive mapping on Lie $C^{ast}$-algebras

Using fixed point method, we prove some new stability results for Lie $(alpha,beta,gamma)$-derivations and Lie $C^{ast}$-algebra homomorphisms on Lie $C^{ast}$-algebras associated with the Euler-Lagrange type additive functional equation begin{align*} sum^{n}_{j=1}f{bigg(-r_{j}x_{j}+sum_{1leq i leq n, ineq j}r_{i}x_{i}bigg)}+2sum^{n}_{i=1}r_{i}f(x_{i})=nf{bigg(sum^{n}_{i=1}r_{i}x_{i}bigg)} end{...

متن کامل

Ideas for a Common Framework for Military M & S and C 3 I Systems

Despite multiple efforts to the contrary, the story of common projects of the Modeling & Simulations (M&S) Community and the Command, Control, Communications, and Intelligence (C3I) Systems Community is more or less limited to the question of building interfaces. This may change in the near future, as each community is engaged in ongoing changes can become a paradigm shift. While the technical ...

متن کامل

NVMeDirect: A User-space I/O Framework for Application-specific Optimization on NVMe SSDs

The performance of storage devices has been increased significantly due to emerging technologies such as Solid State Drives (SSDs) and Non-Volatile Memory Express (NVMe) interface. However, the complex I/O stack of the kernel impedes utilizing the full performance of NVMe SSDs. The application-specific optimization is also difficult on the kernel because the kernel should provide generality and...

متن کامل

Analyzing Web 2.0 Integration with Next Generation Networks for Services Rendering

The Next Generation Networks (NGN) aims to integrate for IP-based telecom infrastructures and provide most advance & high speed emerging value added services. NGN capable to provide higher innovative services, these services will able to integrate communication and Web service into a single platform. IP Multimedia Subsystem, a NGN leading technology, enables a variety of NGN-compliant communica...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2010