In mediated information systems clients and various autonomous sources are brought together by mediators. The mediation paradigm needs powerful and expressive security mechanisms considering the dynamics and conflicting interests of the mediation participants. Firstly, we discuss the security requi rements for mediation with an emphasis on confidentiality and authenticity. We argue for basing the enforcement of these properties on certified personal authorization attributes rather than on identification. Using a public key infrastructure such personal authorization attributes can be bound to asymmetric encryption keys by credentials. Secondly, we propose a general design of secure mediation where credentials are roughly used as follows: clients show their eligibility for receiving requested information by the contained personal authorization attributes, and sources and the mediator guarantee confidentiality by using the contained encryption keys. Thirdly, we refine the general design for a specific approach to mediation, given by our prototype of a Multimedia Mediator, MMM. Among other contributions, we define the authorization model and the specification of query access authorizations within the framework of ODL, as well as the authorization and encryption policies for mediation, and we outline the resulting security architecture of the MMM. We also analyze the achievable security properties including support for anonymity, and we discuss the inevitable tradeoffs between security and mediation functionality.
In an environment of heterogeneous data sources it may be necessary to integrate these in order to provide a single global view to the data. Nowadays this problem is solved by mediators, which are tolerant not only to heterogeneity of the sources, but also of their availability and of structural changes. For some mediation problems it is reasonable to assume the existence of a fixed structured target schema as the global view. In these cases, mismatches of target concepts and source concepts can occur, which make it impossible for a mediator to interpret the data correctly and completely at the same time. We will show how to enforce correct interpretations by imposing constraints on the mappings between the target schema and the source schemas. The strength of such constraints can be decreased in a flexible and controlled way, for the sake of exploiting more sources, and at the cost of potentially loosing assurance in correctness. Additionally, we treat interpretation completeness of sources. A careful specification of data structures and algorithms allows for using mappings of this kind in a generic mediation system. The data structures represent mappings explicitly by linking structural descriptions of source data to the target schema expressed in an object oriented data model.
We present an overview of a large combined querying and retrieval system that performs content-based on-line searches in a large database of multimedia documents (currently text, tables and colour images). Queries are submitted as sentences in natural language and are transformed into the language of the target database. The documents are analyzed semantically for their information content; in a data fusion step the individual pieces of information extracted from these documents are aggregated into cognitively adequate result documents. There is no pre-indexing necessary when new documents are stored into the system. This retains a high degree of flexibility with respect to the questions that may be asked. It implies, however, that both huge amounts of data must be evaluated rapidly and that intelligent caching strategies must be employed. It is therefore mandatory that the system be equipped with dedicated high-speed hardware processors. The complete system is currently available as a prototype; the paper outlines its architecture and gives examples of some real sample queries in the knowledge domain of weather data documents.
Mediation is a powerful paradigm for advanced interoperable information systems. This paper presents the security module of the multimedia mediator which enforces a previously reported approach to secure mediation. In this approach, a user submits cryptographically signed credentials containing both personal authorization attributes and his public encryption key, and data sources decide on the query access on the basis of shown personal authorization attributes and return encrypted answers. The security module uniformly represents the query access authorizations of the sources, controls the intermediate usage of credentials, assists users in submitting appropriate credentials, selects and forwards credentials for subqueries, and exploits credentials for query optimization.
Today's information society needs application speciic up to date information. The electronically available data is organized in a rapidly changing variety of sources like databases, WWW sites, le systems, etc. We need to dynamically integrate the heterogeneous data in order to provide consistent information for a speciic application. Our approach to solve this problem is a mediating system, consisting of a mediator with an internal database system, and several wrappers connected to the data sources. In this paper we will show how we make the internal database system of the mediator do the data integration by employing adequate data structures for linking application level objects and source level data. We will outline the concept of type embedding and its implementation, and then show how it can be used for data integration in a widely distributed environment.
We present a concept of weakly constraining types which balances heterogeneity and fixity of data structures. This concept is designed for a multimedia mediator that uses fixed type declarations on schema level but allows variations of actual structures on instance level. The concept is based on a notion of embedding a fixed type declaration into a variation structure such that essential aspects of the fixed declaration are preserved. Finally we show how multimedia types gain from our type system.
Burkhard Monien合作论文数Institut fur Informatik, Universitat Paderborn1