• DocumentCode
    1959405
  • Title

    A structure preserving approach for securing XML documents

  • Author

    Nabeel, Mohamed ; Bertino, Elisa

  • Author_Institution
    Dept. of Comput. Sci., Purdue Univ., West Lafayette, IN
  • fYear
    2007
  • fDate
    12-15 Nov. 2007
  • Firstpage
    8
  • Lastpage
    15
  • Abstract
    With the widespread adoption of XML as the message format to disseminate content over distributed systems including Web Services and Publish-Subscribe systems, different methods have been proposed for securing messages. We focus on a subset of such systems where incremental updates are disseminated. The goal of this paper is to develop an approach for disseminating only the updated or accessible portions of XML content while assuring confidentiality and integrity at message level. While sending only the updates greatly reduces the bandwidth requirements, it introduces the challenge of assuring security efficiently for partial messages disseminated to intermediaries and clients. We propose a novel localized encoding scheme based on conventional cryptographic functions to enforce security for confidentiality and content integrity at the granularity of XML node level. We also address structural integrity with respect to the complete XML document to which clients have access. Our solution takes every possible measure to minimize indirect information leakage by making the rest of the structure of XML documents to which intermediaries and clients do not have access oblivious. The experimental results show that our scheme is superior to conventional techniques of securing XML documents when the percentage of update with respect to original documents is low.
  • Keywords
    Web services; XML; cryptography; message passing; middleware; Web services; XML document security; cryptographic function; distributed system; indirect information leakage minimization; localized encoding scheme; publish-subscribe system; structure preserving approach; Bandwidth; Computer science; Cryptography; Data security; Encoding; Information security; Publish-subscribe; Scalability; Web services; XML;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Collaborative Computing: Networking, Applications and Worksharing, 2007. CollaborateCom 2007. International Conference on
  • Conference_Location
    New York, NY
  • Print_ISBN
    978-1-4244-1318-8
  • Electronic_ISBN
    978-1-4244-1317-1
  • Type

    conf

  • DOI
    10.1109/COLCOM.2007.4553802
  • Filename
    4553802