首页> 外文会议>Active and passive signatures V >Fine-Grained Policy Control in the U.S. Army Research Laboratory(ARL) MultiModal Signatures Database
【24h】

Fine-Grained Policy Control in the U.S. Army Research Laboratory(ARL) MultiModal Signatures Database

机译:美国陆军研究实验室(ARL)多模签名数据库中的精细策略控制

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

The U.S. Army Research Laboratory (ARL) Multimodal Signatures Database (MMSDB) consists of a number of co-located relational databases representing a collection of data from various sensors. Role-based access to this data is granted to external organizations such as DoD contractors and other government agencies through a client Web portal. In the current MMSDB system, access control is only at the database and firewall level. In order to offer finer grained security, changes to existing user profile schemas and authentication mechanisms are usually needed. In this paper, we describe a software middleware architecture and implementation that allows fine-grained access control to the MMSDB at a dataset, table, and row level. Result sets from MMSDB queries issued in the client portal are filtered with the use of a policy enforcement proxy, with minimal changes to the existing client software and database. Before resulting data is returned to the client, policies are evaluated to determine if the user or role is authorized to access the data. Policies can be authored to filter data at the row, table or column level of a result set. The system uses various technologies developed in the International Technology Alliance in Network and Information Science (ITA) for policy-controlled information sharing and dissemination1. Use of the Policy Management Library provides a mechanism for the management and evaluation of policies to support finer grained access to the data in the MMSDB system. The GaianDB is a policy-enabled, federated database that acts as a proxy between the client application and the MMSDB system.
机译:美国陆军研究实验室(ARL)多模式签名数据库(MMSDB)由许多位于同一位置的关系数据库组成,这些关系数据库表示来自各种传感器的数据集合。通过客户端Web门户将基于数据的角色访问权限授予DoD承包商和其他政府机构等外部组织。在当前的MMSDB系统中,访问控制仅在数据库和防火墙级别。为了提供更细粒度的安全性,通常需要更改现有的用户配置文件架构和身份验证机制。在本文中,我们描述了一种软件中间件体系结构和实现,该体系结构和实现允许在数据集,表和行级别对MMSDB进行细粒度的访问控制。使用策略强制代理过滤来自客户端门户中发出的MMSDB查询的结果集,而对现有客户端软件和数据库的更改最少。在将结果数据返回给客户端之前,将对策略进行评估,以确定是否授权用户或角色访问数据。可以创作策略以过滤结果集的行,表或列级别的数据。该系统使用在网络和信息科学国际技术联盟(ITA)中开发的各种技术来进行政策控制的信息共享和传播1。使用策略管理库提供了一种机制,用于管理和评估策略,以支持对MMSDB系统中的数据进行更细粒度的访问。 GaianDB是启用策略的联合数据库,充当客户端应用程序和MMSDB系统之间的代理。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号