首页> 外文会议>International Conference on Future Data and Security Engineering >A Model-Driven Approach for Enforcing Fine-Grained Access Control for SQL Queries
【24h】

A Model-Driven Approach for Enforcing Fine-Grained Access Control for SQL Queries

机译:一种用于对SQL查询执行细粒度访问控制的模型驱动方法

获取原文

摘要

In this paper we propose a novel, model-driven approach for enforcing fine-grained access control (FGAC) policies when executing SQL queries. More concretely, we define a function SecQuery() that, given a FGAC policy S and a SQL select-statement q, generates a SQL stored-procedure, such that: if a user is authorized, according to S, to execute q, then calling this stored-procedure returns the same result that executing q; otherwise, if a user is not authorized, according to S, to execute q, then calling this stored-procedure signals an error. We have implemented our approach in an open-source project, called SQL Security Injector (SQLSI).
机译:在本文中,我们提出了一种新颖的模型驱动方法,用于在执行SQL查询时强制执行细粒度访问控制(FGAC)策略。更具体地,我们定义了一个函数secquery(),给定FGAC策略s和一个SQL Select-stalal Q,生成一个SQL存储过程,使得:如果用户根据S授权,则执行Q,然后执行q调用此存储过程返回执行Q的相同结果;否则,如果用户未经授权,则执行Q,然后调用此存储过程信号错误。我们在一个名为SQL安全注射器(SQLSI)的开源项目中实现了我们的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号