首页> 外文OA文献 >Idea: Supporting policy-based access control on database systems
【2h】

Idea: Supporting policy-based access control on database systems

机译:想法:在数据库系统上支持基于策略的访问控制

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Applications are increasingly operating on large data sets. This trend creates problems for access control, which in principle restricts the actions that subjects can perform on any item in that data set. Performance issues therefore emerge, typically for operations on entire data sets. Emerging access control models such as attribute-based access control do meet their limitations in this context. Worse, few solutions exist that addresses performance problems while supporting separation of concerns. In this paper, we present a first approach towards addressing this challenge. We propose a middleware architecture that performs policy transformations and query rewriting for externalized policies to optimize the access control process on the data set. We argue that this offers a promising approach for reducing the policy evaluation overhead for access control on large data sets.
机译:应用程序越来越多地在大型数据集上运行。这种趋势给访问控制带来了问题,从原则上讲,它限制了主体可以对该数据集中的任何项目执行的动作。因此出现性能问题,通常是针对整个数据集的操作。在这种情况下,诸如基于属性的访问控制之类的新兴访问控制模型确实满足了它们的限制。更糟糕的是,很少有解决方案能够在支持关注点分离的同时解决性能问题。在本文中,我们提出了应对这一挑战的第一种方法。我们提出了一种中间件体系结构,该结构对外部化策略执行策略转换和查询重写,以优化对数据集的访问控制过程。我们认为这为减少大数据集访问控制的策略评估开销提供了一种有前途的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号