首页> 外文期刊>The Journal of object technology >Model-based characterization of fine-grained accesscontrol authorization for SQL queries
【24h】

Model-based characterization of fine-grained accesscontrol authorization for SQL queries

机译:基于模型的SQL查询的细粒度AccessControl授权的特征

获取原文
       

摘要

We propose a model-based characterization of fine-grained access control (FGAC) authorization for SQL queries. More specifically, we define a predicate AuthQuery() that represents whether a user is authorized by an FGAC-policy to execute a SQL query on a database. It is characteristic of FGAC-policies that access control decisions depend on dynamic information, namely whether the current state of the system satisfies some “authorization constraints”. In our proposal, FGAC- policies are modeled using a dialect of SecureUML, and authorization constraints are specified using the Object Constraint Language (OCL). To illustrate our definition of the predicate AuthQuery(), we provide examples of authorization decisions for different SQL queries, attempted by different users, in different scenarios, and with respect to different FGAC-policies. Interestingly, the availability of mappings from OCL to SQL opens up the possibility of implementing AuthQuery() within the database and, consequently, of enforcing FGAC-policies following a model-driven approach.
机译:我们提出了一种基于模型的SQL查询授权的基于模型的分子授权。更具体地,我们定义了一个谓词authQuery(),其表示用户是否被FGAC策略授权以在数据库上执行SQL查询。它是FGAC-政策的特征,即访问控制决策依赖于动态信息,即系统的当前状态是否满足一些“授权约束”。在我们的建议中,FGAC-策略使用Secureuml的方言进行建模,并且使用对象约束语言(OCL)指定授权约束。为了说明我们对谓词authquery()的定义,我们为不同的SQL查询提供了不同的SQL查询的授权决策示例,不同的用户在不同的场景中尝试以及不同的FGAC策略。有趣的是,OCL到SQL的映射的可用性开辟了在模型驱动的方法之后实现了数据库内的AuthQuery()的可能性,并且因此强制执行FGAC策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号