P. Devi Sravanthi,
Manas Kumar Yogi,
- Assistant Professor, Department of Artificial Intelligence Engineering, Pragati Engineering College, Surampalem, Andhra Pradesh, India
- Assistant Professor, Department of Computer Science and Engineering, Pragati Engineering College, Surampalem, Andhra Pradesh, India
Abstract
The integration of extensible markup language (XML) technologies into advanced database management systems (DBMS) has revolutionized data storage, retrieval, and security paradigms. This comprehensive review examines the critical role of XML-based security mechanisms in protecting sensitive data in contemporary database environments. This study explores various XML security technologies, including XML encryption, XML digital signatures, XML access control models, and XML firewalls, and analyzes their implementation strategies and effectiveness in mitigating database vulnerabilities. Through a systematic analysis of recent developments spanning 2020–2025, this review identifies emerging trends in XML-based authentication protocols, query injection prevention techniques, and schema validation mechanisms. This study further investigates the integration of XML security standards, such as WS-Security, eXtensible access control markup language (XACML), and Security Assertion Markup Language (SAML), into database security architectures. The findings indicate that XML technologies provide robust frameworks for implementing fine-grained access control, ensuring data integrity, and maintaining confidentiality across distributed database systems. This review contributes to the understanding of XML security implementations and provides practical insights for database administrators and security experts.
Keywords: XML, security, attack, DBMS, firewalls, sensitive
[This article belongs to Journal of Advanced Database Management & Systems ]
References
- Wang H, Lakshmanan LVS. Efficient secure query evaluation over encrypted XML databases. In: Dayal U, Whang KY, Lomet DB, Alonso G, Lohman GM, Kersten ML, et al., editors. Proceedings of the 32nd International Conference on Very Large Data Bases; 2006 Sep 12–15; Seoul, Korea. New York: ACM; 2006. p. 127–138.
- Baba MA, Yusuf A, Ahmad A, Maijama’a L. Performance analysis of the encryption algorithms as solution to cloud database security. Int J Comput Appl. 2014 Aug;99(14):24–31. doi:10.5120/17442-8228.
- Jin Y, Kaja KC. XACML implementation based on graph database. In: Lee G, Jin Y, editors. Proceedings of the 34th International Conference on Computers and Their Applications (CATA); 2019 Mar 18–20; Honolulu, HI, USA. EPiC Ser Comput. 2019;58. Red Hook (NY): Curran Associates Inc.; 2019. p. 65–74.
- Takase T, Uramoto N, Baba K. XML digital signature system independent of existing applications. Proceedings 2002 Symposium on Applications and the Internet (SAINT) Workshops, Nara, Japan. 2002. p. 150–157. doi:10.1109/SAINTW.2002.994565.
- Lan Y, Samonte C, Wang X. SAM-based localization method for image copy-move forgery. Proceedings of the 2024 10th International Conference on Computer Technology Applications (ICCTA); 2024 May 15–17; Vienna, Austria. New York (NY): Association for Computing Machinery; 2024. p. 200–208. doi:10.1145/3674558.3674586.
- Lee JG, Whang KY. Secure query processing against encrypted XML data using query-aware decryption. Inf Sci. 2006;176(13):1928-47. doi:10.1016/j.ins.2005.08.001.
- Gou G, Chirkova R. Efficiently querying large XML data repositories: a survey. IEEE Trans Knowl Data Eng. 2007;19(10):1381–1403. doi:10.1109/TKDE.2007.1060.
- Jing Z. The analysis of XML technology in network security. 2010 International Symposium on Intelligence Information Processing and Trusted Computing, Huanggang, China. 2010. p. 701–704. doi:10.1109/IPTC.2010.18.
- Gardazi SU, Shahid AA. Compliance-driven architecture for healthcare industry. Int J Adv Comput Sci Appl. 2017;8(5). doi:10.14569/IJACSA.2017.080571.
- Padmanabhuni S, Adarkar H. Security in service-oriented architecture: issues, standards, and implementations. In: Nemati H, editor. Information Security and Ethics: Concepts, Methodologies, Tools, and Applications. Hershey (PA): IGI Global; 2008. p. 496–512. doi:10.4018/978-1-59904-937-3.ch039.
- Martin MC, Lam MS. Automatic generation of XSS and SQL injection attacks with goal-directed model checking. Proceedings of the 17th USENIX Security Symposium, July 28–August 1, 2008, San Jose, CA, USA. Berkeley (CA): USENIX Association; 2008. p. 31–43.
- Morales-Sandoval M, Cabello MH, Marin-Castro HM, Compean JLG. Attribute-based encryption approach for storage, sharing and retrieval of encrypted data in the cloud. IEEE Access. 2020;8:170101–170116. doi:10.1109/ACCESS.2020.3023893.
- Ren Y, Boukerche A, Mokdad L. Performance analysis of a selective encryption algorithm for wireless ad hoc networks. 2011 IEEE Wireless Communications and Networking Conference, Cancun, Mexico. 2011. p. 1038–1043. doi:10.1109/WCNC.2011.5779278.
- Sommerhalder M. Hardware security module. In: Mulder V, Mermoud A, Lenders V, Tellenbach B, editors. Trends in Data Protection and Encryption Technologies. Cham: Springer; 2023. p. 83–87. doi:10.1007/978-3-031-33386-6_16.
- Mohan S, SenGupta A, Wu Y. A framework for access control for XML. ACM Trans Inf Syst Secur. 2006;5:1–38.
- Govindarajan V. A novel system for managing encrypted data using searchable encryption techniques. Int J Adv Comput Sci Appl. 2025;16(3). doi:10.14569/IJACSA.2025.0160303.
- Ullah F, Naeem H, Jabbar S, Khalid S, Latif MA, Al-Turjman F, et al. Cyber security threats detection in internet of things using deep learning approach. IEEE Access. 2019;7:124379–124389. doi:10.1109/ACCESS.2019.2937347.
- Müller J, Oupický J. Post-quantum XML and SAML single sign-on. Proc Priv Enhancing Technol. 2024;2024(4):525–543. doi:10.56553/popets-2024-0128.
- Gilbert C, Gilbert MA. The integration of blockchain technology into database management systems for enhanced security and transparency. Int Res J Adv Eng Sci. 2024;9(4):316–334.
- Chellu R. Adaptive SSL certificate lifecycle management for enhanced cybersecurity. Int J Appl Eng Technol. 2023;5(2):621–635.
- Damiani E, De Capitani di Vimercati S, Paraboschi S, Samarati P. A fine-grained access control system for XML documents. ACM Trans Inf Syst Secur. 2002;5(2):169–202. doi:10.1145/505586.505590.

Journal of Advanced Database Management & Systems
| Volume | 13 | |
| Issue | 01 | |
| Received | 13/02/2026 | |
| Accepted | 20/02/2026 | |
| Published | 20/03/2026 | |
| Publication Time | 35 Days |