Enforcing Access Control in Web-Based Social Networks

被引:133
作者
Carminati, Barbara [1 ]
Ferrari, Elena [1 ]
Perego, Andrea [1 ]
机构
[1] Univ Insubria, Dipartimento Informat & Commun, I-21100 Varese, Italy
关键词
Design; Theory; Access control; Semantic Web; social networks; SYSTEMS; TRUST;
D O I
10.1145/1609956.1609962
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this article, we propose an access control mechanism for Web-based social networks, which adopts a rule-based approach for specifying access policies on the resources owned by network participants, and where authorized users are denoted in terms of the type, depth, and trust level of the relationships existing between nodes in the network. Different from traditional access control systems, our mechanism makes use of a semidecentralized architecture, where access control enforcement is carried out client-side. Access to a resource is granted when the requestor is able to demonstrate being authorized to do that by providing a proof. In the article, besides illustrating the main notions on which our access control model relies, we present all the protocols underlying our system and a performance study of the implemented prototype.
引用
收藏
页数:38
相关论文
共 40 条