首页> 外文会议>International Conference on Very Large Data Bases(VLDB 2004); 20040831-0903; Toronto(CA) >A Multi-Purpose Implementation of Mandatory Access Control in Relational Database Management Systems
【24h】

A Multi-Purpose Implementation of Mandatory Access Control in Relational Database Management Systems

机译:关系数据库管理系统中强制访问控制的多用途实现

获取原文
获取原文并翻译 | 示例

摘要

Mandatory Access Control (MAC) implementations in Relational Database Management Systems (RDBMS) have focused solely on Multilevel Security (MLS). MLS has posed a number of challenging problems to the database research community, and there has been an abundance of research work to address those problems. Unfortunately, the use of MLS RDBMS has been restricted to a few government organizations where MLS is of paramount importance such as the intelligence community and the Department of Defense. The implication of this is that the investment of building an MLS RDBMS cannot be leveraged to serve the needs of application domains where there is a desire to control access to objects based on the label associated with that object and the label associated with the subject accessing that object, but where the label access rules and the label structure do not necessarily match the MLS two security rules and the MLS label structure. This paper introduces a flexible and generic implementation of MAC in RDBMS that can be used to address the requirements from a variety of application domains, as well as to allow an RDBMS to efficiently take part in an end-to-end MAC enterprise solution. The paper also discusses the extensions made to the SQL compiler component of an RDBMS to incorporate the label access rules in the access plan it generates for an SQL query, and to prevent unauthorized leakage of data that could occur as a result of traditional optimization techniques performed by SQL compilers.
机译:关系数据库管理系统(RDBMS)中的强制性访问控制(MAC)实现仅专注于多级安全性(MLS)。 MLS给数据库研究界提出了许多具有挑战性的问题,并且已经进行了大量的研究工作来解决这些问题。不幸的是,MLS RDBMS的使用仅限于少数几个MLS最重要的政府组织,例如情报界和国防部。这意味着无法利用构建MLS RDBMS的投资来满足需要基于与该对象关联的标签和与该对象关联的标签的对象来控制对对象的访问的应用程序域的需求。对象,但标签访问规则和标签结构不一定与MLS两个安全规则和MLS标签结构匹配。本文介绍了RDBMS中MAC的灵活通用实现,可用于满足各种应用领域的需求,并允许RDBMS有效地参与端到端MAC企业解决方案。本文还讨论了对RDBMS的SQL编译器组件所做的扩展,以将标签访问规则纳入其为SQL查询生成的访问计划中,并防止由于执行传统优化技术而导致的未授权数据泄漏。由SQL编译器。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号