The increasing use of graph-structured data for business- and privacy-critical applications requires sophisticated, flexible and fine-grained authorization and access control. Currently, role-based access control is supported in graph databases, where access to objects is restricted via roles. This does not take special properties of graphs into account such as vertices and edges along the path between a given subject and resource. In previous iterations of our research, we started to design an authorization policy language and access control model, which considers the specification of graph paths and enforces them in the multi-model database ArangoDB. Since this approach is promising to consider graph characteristics in data protection, we improve the language in this work to provide flexible path definitions and specifying edges as protected resources. Furthermore, we introduce a method for a datastore-independent policy enforcement. Besides discussing the latest work in our XACML4G model, which is an extension to the Extensible Access Control Markup Language (XACML), we demonstrate our prototypical implementation with a real case and give an outlook on performance.
翻译:图结构数据在关键业务和隐私敏感型应用中的日益普及,要求实现精细化、灵活且复杂的授权与访问控制。当前图数据库主要采用基于角色的访问控制,通过角色限制对对象的访问,但未能考虑图特有的属性,例如给定主体与资源之间路径上的顶点和边。在前期研究中,我们初步设计了一种授权策略语言及访问控制模型,该模型支持图路径的规范化描述,并在多模型数据库ArangoDB中实施执行。鉴于该方法在数据保护中充分融合了图特性,本研究通过提供灵活的路径定义并支持将边作为受保护资源,进一步改进了该语言。此外,我们提出了一种数据存储无关的策略执行方法。在介绍XACML4G模型(可扩展访问控制标记语言XACML的扩展)最新工作的同时,我们通过实际案例展示了原型实现,并讨论了性能展望。