【24h】

A Flexible Database Security System using Multiple Access Control Policies

机译:使用多种访问控制策略的灵活的数据库安全系统

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Due to various requirements for the user access control to large databases in the hospitals and the banks,database security has been emphasized. There are many security models for database systems using wide variety of policy-based access control methods. However, they are not functionally enough to meet the requirements for the complicated and various types of access control. In this paper, we propose a database security system that can individually control user access to data groups of various sizes and is suitable for the situation where the user's access privilege to arbitrary data is changed frequently.Data group(s) in different sizes d is defined by the table name(s), attribute(s) and/or record key(s), and the access privilege is defined by security levels, roles and polices.The proposed system operates in two phases. The first phase is composed of a modified MAC(Mandatory Access Control) model and RBAC(Role-Based Access Control) model. A user can access any data that has lower or equal security levels, and that is accessible by the roles to which the user is assigned. All types of access mode are controlled in this phase. In the second phase, a modified DAC(Discretionary Access Control) model is applied to non-accessible data from the result obtained at the first phase. For this purpose, we also defined the user group s that can be characterized by security levels, roles or any partition of users. The policies represented in the form of Block(s, d, r) were also defined and used to control access mode. With this proposed security system, more individual users can be flexibly controlled, while other access mode can be controlled as usual. An implementation example for a database system that manages specimen and clinical information is presented.
机译:由于对医院和银行中大型数据库的用户访问控制有各种要求,因此已经强调了数据库安全性。使用多种基于策略的访问控制方法的数据库系统有许多安全模型。但是,它们在功能上不足以满足复杂和各种类型的访问控制的要求。在本文中,我们提出了一种数据库安全系统,该系统可以单独控制用户对各种大小的数据组的访问,并且适合于用户对任意数据的访问特权频繁更改的情况。由表名,属性和/或记录键定义,访问权限由安全级别,角色和策略定义。拟议的系统分两个阶段运行。第一阶段由修改后的MAC(强制访问控制)模型和RBAC(基于角色的访问控制)模型组成。用户可以访问任何具有较低或相等安全级别的数据,并且可以通过为其分配角色来访问这些数据。在此阶段,将控制所有类型的访问模式。在第二阶段中,根据在第一阶段获得的结果,将修改后的DAC(自由访问控制)模型应用于不可访问的数据。为此,我们还定义了可以由安全级别,角色或用户的任何分区来表征的用户组。还定义了以块(s,d,r)形式表示的策略,并将其用于控制​​访问模式。利用该提议的安全系统,可以灵活地控制更多的个人用户,而可以照常控制其他访问模式。给出了一个管理样本和临床信息的数据库系统的实现示例。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号