• DocumentCode
    2919428
  • Title

    A Framework for a File View Model in Intranets

  • Author

    Ai, Yong ; Dong, Hongbin ; Liang, Yiwen ; McKay, R.I.

  • Author_Institution
    Comput. Sch., Wuhan Univ., Wuhan, China
  • fYear
    2009
  • fDate
    24-26 Nov. 2009
  • Firstpage
    976
  • Lastpage
    981
  • Abstract
    Today, a new security problem is arising in intranets. The threats from inside an organization account for a rapidly increasing proportion of losses. The DAC (discretionary access control) model, which is the primary access control mechanism in most intranets, is main responsibility for this state of affairs. Users can make a duplicate of a confidential document for which they only have read authorization. They can then grant access rights the replication to others who did not previously have authorization. This transformation of authorizations would result in the contents being divulged to unauthorized users. This paper proposes a concept of ¿file view¿ to solve this security problem in intranets. First, the paper proposes a hierarchy of file views which are used to structure availability of reference to database views. However there are some challenges in extending this proposal to file systems because of differences between the two. The paper proposes a framework for a file view model to solve these challenges. Finally, under three assumptions, it discusses access control and proposes read and write process algorithms for secured access in this framework.
  • Keywords
    authorisation; database management systems; intranets; confidential document; database views; discretionary access control model; file view model; intranets; read authorization; read process algorithm; security problem; write process algorithm; Access control; Authorization; Computer security; Data security; Databases; File systems; Information security; Information technology; Linux; Operating systems; Access Control; Access Tracing; File View; Information Security; Mapping Mechanism;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Sciences and Convergence Information Technology, 2009. ICCIT '09. Fourth International Conference on
  • Conference_Location
    Seoul
  • Print_ISBN
    978-1-4244-5244-6
  • Electronic_ISBN
    978-0-7695-3896-9
  • Type

    conf

  • DOI
    10.1109/ICCIT.2009.63
  • Filename
    5369544