首页> 外文会议>IEEE Military Communications Conference >Enforcing agile access control policies in relational databases using views
【24h】

Enforcing agile access control policies in relational databases using views

机译:使用视图在关系数据库中实施敏捷访问控制策略

获取原文

摘要

Access control is used in databases to prevent unauthorized retrieval and tampering of stored data, as defined by policies. Various policy models provide different protections and guarantees against illegal accesses, but none is able to offer a universal fit for all access control needs. Therefore, the static nature of access control mechanisms deployed in commercial databases limit the security guarantees provided. They require time-consuming and error-prone efforts to adapt access control policies to evolving security contexts. In contrast, we propose a fully automated and agile approach to access control enforcement in relational databases. We present tractable algorithms that enforce any policy expressible using the high-level syntax of the Authorization Specification Language. This includes complex policies involving information flow control or user history dependencies. Our method does not require any modification to the database schema or user queries, thus allowing for a transparent implementation in existing systems. We demonstrate our findings by formulating two classic access control models: the Bell-LaPadula model and the Chinese Wall policy.
机译:数据库中使用访问控制来防止未经授权的检索和篡改存储的数据(如策略所定义)。各种策略模型提供了针对非法访问的不同保护和保证,但没有一个能够为所有访问控制需求提供通用的模型。因此,部署在商业数据库中的访问控制机制的静态性质限制了所提供的安全性保证。他们需要耗时且容易出错的工作,以使访问控制策略适应不断发展的安全环境。相比之下,我们提出了一种自动化的敏捷方法来在关系数据库中实施访问控制。我们提出了易于处理的算法,这些算法使用授权规范语言的高级语法来实施可表达的任何策略。这包括涉及信息流控制或用户历史记录依赖性的复杂策略。我们的方法不需要对数据库架构或用户查询进行任何修改,因此可以在现有系统中实现透明的实现。我们通过制定两个经典的访问控制模型来证明我们的发现:Bell-LaPadula模型和中国墙政策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号