1 Spatial Data on the Web: Issues and Challenges
9
flexibility or require taking into account additional security properties [2]. Such a
need has resulted in various extensions to traditional security mechanisms over the
past decade, which have been driven by the following three main factors:
• New Data Types. Information systems were originally defined to efficiently manage alphanumeric data. However, today most applications need to manage multimedia data in addition to traditional data. For example, medical applications,
digital libraries, or applications in the cultural heritage domain should manage
in an integrated way data from different media (such as audio, images, text, and
video) and with totally different characteristics and requirements. The main difference with respect to traditional data is that such data are unstructured, and
as such, new data models should be devised to represent their semantics within
a data management system, and new security solutions should be devised for
their protection. Additionally, the Web has increased the types of data that need
to be managed, being XML [26] the de facto standard for data representation
and transmission over the Web. Also spatial data have further security requirements with respect to traditional data, which must be taken into account when
developing a security mechanism. For instance, when dealing with spatial data,
it is important to take into account the spatial dimension that access permissions
usually have: a user can be authorized to display only maps referring to a particular region, or can be authorized to access different data depending on his/her
position.
• New Architectures. The widespread use of the Internet and other network facilities has made possible the adoption of new architectures, besides the traditional
client–server one. In particular, database management systems are today moving from a centralized architecture to more distributed ones. Examples in this
direction are parallel or distributed databases, peer-to-peer systems, third-party
architectures, or architectures based on Web services. Clearly, dealing with distributed architectures makes data protection more difficult. In a centralized environment, the core component of any security mechanism is the access control
module that is hosted on a trusted site, i.e. the server intercepts each request to
access the data and authorizes only those meeting the requirements of the specified security policies. Such a simple solution cannot easily be applied when it is
not possible to rely on a single trusted server.
• New Applications. Many advanced application environments, such as distributed
digital libraries, workflow applications, groupware, data warehousing, and data
mining applications, have new security requirements. For instance, in a digital
library, environment ownership protection is a fundamental requirement, besides
confidentiality and authenticity. The requirements of these new applications cannot be adequately supported by standard security mechanisms that are tailored to
few, specific security policies. In most cases, either the organization is forced to
adopt the specific mechanism built into the data management system, or the new
requirements must be implemented as application programs. Both situations are
clearly unacceptable. Thus, there is the need for developing security mechanisms
specifically tailored for these new environments.
Précédent

- 311/317

Suivant