Adequate means for viewing, browsing and searching knowledge graphs (KGs) and restricting the access of users are a crucial limiting factor for KGs. To address these issues, this paper presents a view concept and role-based access control (RBAC) for ontologies and KGs. The view concept allows for defining different lenses on a KG, which reduce the complexity to better readable subsets of a KG. Views can be defined with RDF and SHACL. Roles defined in a semantic data catalog can grant user groups access to views. SHACL-defined views combined with a RBAC approach are a novel concept. This combination can realize an expressive access control for KGs, which makes sure that user groups can only see and/or change the information that they are permitted to. It allows for a comprehensive and flexible access control, with different user groups having access to different subsets of a KG. Yet, it is simple to realize, apply and maintain. The view concept and RBAC has been implemented at Bosch and is usable by more than 100,000 Bosch employees. It could successfully be demonstrated that views can significantly improve KG UIs by their different, simplified and specialized lenses that they provide.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Views, Semantic Data Catalog and Role-Based Access Control for Ontologies and Knowledge Graphs

  • Henrik Dibowski

摘要

Adequate means for viewing, browsing and searching knowledge graphs (KGs) and restricting the access of users are a crucial limiting factor for KGs. To address these issues, this paper presents a view concept and role-based access control (RBAC) for ontologies and KGs. The view concept allows for defining different lenses on a KG, which reduce the complexity to better readable subsets of a KG. Views can be defined with RDF and SHACL. Roles defined in a semantic data catalog can grant user groups access to views. SHACL-defined views combined with a RBAC approach are a novel concept. This combination can realize an expressive access control for KGs, which makes sure that user groups can only see and/or change the information that they are permitted to. It allows for a comprehensive and flexible access control, with different user groups having access to different subsets of a KG. Yet, it is simple to realize, apply and maintain. The view concept and RBAC has been implemented at Bosch and is usable by more than 100,000 Bosch employees. It could successfully be demonstrated that views can significantly improve KG UIs by their different, simplified and specialized lenses that they provide.