Personalizable Ontology Based Access Control

Volume: 23 Number: 4 March 19, 2010
EN

Personalizable Ontology Based Access Control

Abstract

The main idea of Semantic Web is creating web pages which are also understood by machines and using ontologies to unify data. Improving a secure Semantic Web is one of the main works in Semantic Web research area. For this purpose, policies are used. Policy is a set of rules and provides an access control mechanism for a resource without making any change in that resource. Policy management in Semantic Web is used to define rules for accessing a resource and to provide users to interpret and comply with these rules. One of the key features to develop successful personalized Semantic Web applications is to build user profiles. In this paper, we developed an Ontology-Based Access Control (OBAC) model. This model represents domain and profile information semantically and has a profile based policy approach in order to achieve a personalized policy management for Semantic Web. We store personal information in profiles and model this information semantically to make it part of access control model. Thus, we created two kinds of policies: domain and profile based policies. We implemented an Ontology-Based Access Control application which creates, modifies, and deletes policy ontologies. Policy conflicts are also resolved to provide fine-grained policies in OBAC model. The main contributions of this work are: defining semantically rich resource and entity policies for an OntologyBased Access Control mechanism and making use of these policies in terms of the personalization scope.

 

 Key Words: Semantic Web, Ontology, Policy, Profile, Personalization, Conflict Resolution.

Keywords

References

  1. Finin, T. et al., “ROWLBAC - Representing Role Based Access Control in OWL”, Proceedings of the 13th Symposium on Access Control Models and Technologies, Colorado, USA (2008).
  2. Tonti, G., Bradshaw, J. M., Jeffers, R., Monranari, R., Suri, N., Uszok, A., “Semantic Web Languages for Policy Representation and Reasoning: A Comparison of KaoS, Rei, and Ponder”, 2nd International Semantic Web Conference (ISWC 2003), 419-437 (2003).
  3. Kagal, L., Finin, T., Joshi, A., “A Policy Language for a Pervasive Computing Environment”, POLICY '03: Proceedings of the 4th IEEE International Workshop on Policies for Distributed Systems and Networks, 63 (2003).
  4. Uszok, A., Bradshaw, J. M., Jeffers, R., “KAoS: A Policy and Domain Services Framework for Grid Computing and Semantic Web Services”, Second International Conference on Trust Management, Springer-Verlag (2004).
  5. Kagal, L., Finin, T., Joshi, A., “A Policy Based Approach to Security for the Semantic Web”, 2nd International Semantic Web Conference (ISWC 2003), Sanibal Island, Florida, USA 402-418 (2003).
  6. Cuppens, F., Miège, A., “Modelling Contexts in the Or-BAC Model”, 19th Annual Computer Security Applications Conference (2003).
  7. Yuan, E., Tong, J., “Attributed Based Access Control (ABAC) for Web Services”, In ICWS’05: IEEE International Conference on Web Services 569 (2005).
  8. Jrad, Z., Aufaure, M.A., “Personalized Interfaces for a Semantic Web Portal”, Tourism Information Search, In KES 2007/WIRN 2007, Part III, LNAI 4694, 695-702 (2007).

Details

Primary Language

English

Subjects

-

Journal Section

-

Publication Date

March 19, 2010

Submission Date

March 19, 2010

Acceptance Date

-

Published in Issue

Year 2010 Volume: 23 Number: 4

APA
Can, Ö., Bursa, O., & Ünalır, M. (2010). Personalizable Ontology Based Access Control. Gazi University Journal of Science, 23(4), 465-474. https://izlik.org/JA72TD34AC
AMA
1.Can Ö, Bursa O, Ünalır M. Personalizable Ontology Based Access Control. Gazi University Journal of Science. 2010;23(4):465-474. https://izlik.org/JA72TD34AC
Chicago
Can, Özgü, Okan Bursa, and Murat Ünalır. 2010. “Personalizable Ontology Based Access Control”. Gazi University Journal of Science 23 (4): 465-74. https://izlik.org/JA72TD34AC.
EndNote
Can Ö, Bursa O, Ünalır M (September 1, 2010) Personalizable Ontology Based Access Control. Gazi University Journal of Science 23 4 465–474.
IEEE
[1]Ö. Can, O. Bursa, and M. Ünalır, “Personalizable Ontology Based Access Control”, Gazi University Journal of Science, vol. 23, no. 4, pp. 465–474, Sept. 2010, [Online]. Available: https://izlik.org/JA72TD34AC
ISNAD
Can, Özgü - Bursa, Okan - Ünalır, Murat. “Personalizable Ontology Based Access Control”. Gazi University Journal of Science 23/4 (September 1, 2010): 465-474. https://izlik.org/JA72TD34AC.
JAMA
1.Can Ö, Bursa O, Ünalır M. Personalizable Ontology Based Access Control. Gazi University Journal of Science. 2010;23:465–474.
MLA
Can, Özgü, et al. “Personalizable Ontology Based Access Control”. Gazi University Journal of Science, vol. 23, no. 4, Sept. 2010, pp. 465-74, https://izlik.org/JA72TD34AC.
Vancouver
1.Özgü Can, Okan Bursa, Murat Ünalır. Personalizable Ontology Based Access Control. Gazi University Journal of Science [Internet]. 2010 Sep. 1;23(4):465-74. Available from: https://izlik.org/JA72TD34AC