whole semantics of OWL. Thus, the ontologies
could experience refinement based on practical
needs. SBAC relies on the Semantic Web layers.
The standards for some layers are still in active
discussion and research. The provided feasibility
study illustrates benefits of orientation to Semantic
Web in reusability and expressivity. In general, the
results are quite promising. The automated inferring
makes the enforcement mechanism and the whole
SBAC intelligent and flexible.
Presented in the paper ideas have clear practical
and research implications. SBAC is an ambitious
target. It further demands prototyping of ideas,
reference implementations, and industrial
deployments and evaluations. This should aim at
rigorous and convincing specification of advantages.
The application of SBAC seems to be promising
in areas where Semantic Web emerges and resources
have their semantic annotations according to
ontologies, for example multi-agent systems,
semantic web services, semantic web portals, social
networks, collaborative tools, etc. Semantic web
services and agent technologies are the most
promising because these environments already have
means for ontologies and semantic annotations of
resources (agents and services) and of operations
(service processes and agent speech acts).
ACKNOWLEDGEMENTS
We are grateful for the financial support to the
Rector and to the Department of Mathematical
Information Technology, University of Jyväskylä.
REFERENCES
Berners-Lee, T., Hendler, J., and Lassila, O., 2001. The
Semantic Web. Scientific American, Vol. 284, No. 5,
pp. 34-43.
Gruber, T., 1993. A translation approach to portable
ontologies. Knowledge Acquisition, 5(2): 199-220.
McGuinness, D., and Harmelen, F., (eds.). 2004. OWL
Web Ontology Language Overview. W3C
Recommendation, http://www.w3.org/TR/owl-
features/
Moses, T., (ed.). 2005. eXtensible Access Control Markup
Language (XACML) Version 2.0. OASIS Standard.
Nadalin, A., Kaler, C., Monzillo, R., Hallam-Baker, P.,
(eds.). 2006. Web Services Security: SOAP Message
Security 1.1 (WS-Security 2004). OASIS Standard.
Naumenko A., Nikitin S., Terziyan V., Zharko A., 2005.
Strategic Industrial Alliances in Paper Industry: XML-
vs. Ontology-Based Integration Platforms, The
Learning Organization, Special Issue on: Semantic
and Social Aspects of Learning in Organizations,
Emerald Publishers, Vol. 12, No. 5, pp. 492-514.
Naumenko A., Katasonov A., Terziyan V., 2007. A
Security Framework for Smart Ubiquitous Industrial
Resources, J.P. Müller and K. Mertins (Eds.), In Proc.
of the 3rd Int. Conf.. on Interoperability for Enterprise
Software and Applications, 13 pp. (In press).
Naumenko, A. and Luostarinen, K., 2006. Access Control
Policies in (Semantic) Service-Oriented Architecture,
Schaffert S. and Sure Y. (Eds.), In Semantic Systems
From Visions to Applications, Proc. of the
SEMANTICS 2006, Austrian Computer Society,
Vienna, Austria, pages 49-62.
Naumenko, A., 2006. Contextual rules-based access
control model with trust, Shoniregan C. and
Logvynovskiy A. (Eds.), In Proc. of the Int.
Conference for Internet Technology and Secured
Transactions, e-Centre for Infonomics, London, UK,
ISBN 0-9546628-2-2, pages 68-75.
O’Reilly T., 2005. What Is Web 2.0 Design Patterns and
Business Models for the Next Generation of Software,
http://www.oreillynet.com/pub/a/oreilly/tim/news/200
5/09/30/what-is-web-20.html.
Patel-Schneider, P., Hayes, P., and Horrocks, I., (eds.).
2004. OWL Web Ontology Language Semantics and
Abstract Syntax. W3C Recommendation,
http://www.w3.org/TR/owl-absyn/
Prud'hommeaux, E., and Seaborne, A. (eds.). 2006.
SPARQL Query Language for RDF. W3C Candidate
Recommendation, http://www.w3.org/TR/rdf-sparql-
query/
Qin, L. and Atluri, V., 2003. Concept-level access control
for the Semantic Web. In Proc. of the 2003 ACM
Workshop on XML Security XMLSEC '03. ACM Press,
New York, NY, 94-103.
Tonti, G., Bradshaw, J., Jeffers, R., Montanari, R., Suri,
R., and Uszok, A., 2003. Semantic web languages for
policy representation and reasoning: A comparison of
KAoS, Rei, and Ponder. In Proc. of the Int. Semantic
Web Conference, pp. 419--437.
Wang, X., Lao, G., DeMartini, T., Reddy, H., Nguyen, M.,
and Valenzuela, E., 2002. XrML -- eXtensible rights
Markup Language. In Proc. of the ACM Workshop on
XML Security. XMLSEC '02. ACM Press, New York,
NY, pp. 71-79.
Yagüe, M., Gallardo, M., and Maña, A., 2005. Semantic
Access Control Model: A Formal Specification, In
Lecture Notes in Computer Science, Springer, Volume
3679, pp. 24-43,
Yagüe, M., Maña, A., López, J., and Troya, J., 2003.
Applying the Semantic Web Layers to Access Control.
In Proc. of the Int. Workshop on Web Semantics, IEEE
Computer Society Press, pages 47–63.
Yergeau, F., Bray, T., Paoli, J., Sperberg-McQueen, C.,
and Maler, E., 2004. Extensible Markup Language
(XML) 1.0 (Third Edition). W3C Recommendation,
http://www.w3.org/TR/2004/REC-xml-20040204/
SEMANTICS-BASED ACCESS CONTROL - Ontologies and Feasibility Study of Policy Enforcement Function
155