Access control for Linked Data applications
Pasi Mustonen · Tampere University of Technology Institutional Repository · 2013
This thesis investigates how access control can be implemented in applications which utilize Linked Data. From the viewpoint of access control the relevant subject is, instead of Linked Open Data, specifically Linked Closed Data. The research question was scrutinised by implementing with Java programming language a module, called AccessController, with which applications can retrieve data from servers regardless if the data is open or closed. The module also manages credentials of the end-user by storing the credentials as encrypted in a file. For closed data protected with OAuth 2.0, the module offers an option to grant access tokens for an untrusted third-party application. With access tokens the untrusted can retrieve data owned by the granter. The module was also used as a library when implementing a Apache Ant task. In an Ant pipeline the task has the same features as the module has in a Java application. The AccessController module meets its requirements well. However, the most significant weakness is that the expiring time of access tokens cannot be controlled.