Title :
A content-based authorization model for digital libraries
Author :
Adam, Nabil R. ; Atluri, Vijayalakshmi ; Bertino, Elisa ; Ferrari, Elena
Author_Institution :
CIMIC & MS/IS Dept., Rutgers Univ., Newark, NJ, USA
Abstract :
Digital libraries (DLs) introduce several challenging requirements with respect to the formulation, specification and enforcement of adequate data protection policies. Unlike conventional database environments, a DL environment is typically characterized by a dynamic user population, often making accesses from remote locations, and by an extraordinarily large amount of multimedia information, stored in a variety of formats. Moreover, in a DL environment, access policies are often specified based on user qualifications and characteristics, rather than on user identity (e.g. a user can be given access to an R-rated video only if he/ she is more than 18 years old). Another crucial requirement is the support for content-dependent authorizations on digital library objects (e.g. all documents containing discussions on how to operate guns must be made available only to users who are 18 or older). Since traditional authorization models do not adequately meet the access control requirements typical of DLs, we propose a content-based authorization model that is suitable for a DL environment. Specifically, the most innovative features of our authorization model are: (1) flexible specification of authorizations based on the qualifications and (positive and negative) characteristics of users, (2) both content-dependent and content-independent access control to digital library objects, and (3) the varying granularity of authorization objects ranging from sets of library objects to specific portions of objects
Keywords :
authorisation; content-based retrieval; digital libraries; multimedia databases; authorization object granularity; content-based authorization model; content-dependent access control; content-independent access control; data access policies; data protection policies; digital libraries; dynamic user population; flexible specification; information storage formats; multimedia information; remote access; user characteristics; user qualifications; Authorization; Software libraries;
Journal_Title :
Knowledge and Data Engineering, IEEE Transactions on