Views, Semantic Data Catalog and Role-Based Access Control for Ontologies and Knowledge Graphs
摘要
Adequate means for viewing, browsing and searching knowledge graphs (KGs) and restricting the access of users are a crucial limiting factor for KGs. To address these issues, this paper presents a view concept and role-based access control (RBAC) for ontologies and KGs. The view concept allows for defining different lenses on a KG, which reduce the complexity to better readable subsets of a KG. Views can be defined with RDF and SHACL. Roles defined in a semantic data catalog can grant user groups access to views. SHACL-defined views combined with a RBAC approach are a novel concept. This combination can realize an expressive access control for KGs, which makes sure that user groups can only see and/or change the information that they are permitted to. It allows for a comprehensive and flexible access control, with different user groups having access to different subsets of a KG. Yet, it is simple to realize, apply and maintain. The view concept and RBAC has been implemented at Bosch and is usable by more than 100,000 Bosch employees. It could successfully be demonstrated that views can significantly improve KG UIs by their different, simplified and specialized lenses that they provide.