首页> 外文会议>IEEE Military Communications Conference >Enforcing agile access control policies in relational databases using views
【24h】

Enforcing agile access control policies in relational databases using views

机译:使用视图强制执行关系数据库中的敏捷访问控制策略

获取原文

摘要

Access control is used in databases to prevent unauthorized retrieval and tampering of stored data, as defined by policies. Various policy models provide different protections and guarantees against illegal accesses, but none is able to offer a universal fit for all access control needs. Therefore, the static nature of access control mechanisms deployed in commercial databases limit the security guarantees provided. They require time-consuming and error-prone efforts to adapt access control policies to evolving security contexts. In contrast, we propose a fully automated and agile approach to access control enforcement in relational databases. We present tractable algorithms that enforce any policy expressible using the high-level syntax of the Authorization Specification Language. This includes complex policies involving information flow control or user history dependencies. Our method does not require any modification to the database schema or user queries, thus allowing for a transparent implementation in existing systems. We demonstrate our findings by formulating two classic access control models: the Bell-LaPadula model and the Chinese Wall policy.
机译:访问控制用于数据库中,以防止未经授权的检索和篡改存储的数据,如策略所定义。各种政策模式提供不同的保护和保证对非法访问,但无能够为所有访问控制需求提供通用符合。因此,在商业数据库中部署的访问控制机制的静态性质限制了所提供的安全保证。它们需要耗时和易于易于努力来调整访问控制策略到不断发展的安全环境。相比之下,我们提出了一种全自动和敏捷的方法来访问关系数据库中的控制执行。我们呈现了易于执行使用授权规范语言的高级语法来执行任何策略的遗传算法。这包括涉及信息流控制或用户历史依赖性的复杂策略。我们的方法不需要对数据库架构或用户查询的任何修改,从而允许在现有系统中透明实现。我们通过制定两种经典访问控制模型:贝尔拉帕德图模型和中国墙上政策,展示了我们的研究结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号