首页> 外文OA文献 >Runtime values driven by access control policies: statically enforced at the level of relational business tiers
【2h】

Runtime values driven by access control policies: statically enforced at the level of relational business tiers

机译:由访问控制策略驱动的运行时值:在关系业务层级别上静态实施

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。
获取外文期刊封面目录资料

摘要

Access control is a key challenge in software engineering, especially in relational database applications. Current access control techniques are based on additional security layers designed by security experts. These additional security layers do not take into account the necessary business logic leading to a separation between business tiers and access control mechanisms. Moreover, business tiers are built from commercial tools (ex: Hibernate, JDBC, ODBC, LINQ), which are not tailored to deal with security aspects. To overcome this situation several proposals have been presented. In spite of their relevance, they do not support the enforcement of access control policies at the level of the runtime values that are used to interact with protected data. Runtime values are critical entities because they play a key role in the process of defining which data is accessed. In this paper, we present a general technique for static checking, at the business tier level, the runtime values that are used to interact with databases and in accordance with the established access control policies. The technique is applicable to CRUD (create, read, update and delete) expressions and also to actions (update and insert) that are executed on data retrieved by Select expressions. A proof of concept is also presented. It uses an access control platform previously developed, which lacks the key issue of this paper. The collected results show that the presented approach is an effective solution to enforce access control policies at the level of runtime values that are used to interact with data residing in relational databases.
机译:访问控制是软件工程中的一个关键挑战,特别是在关系数据库应用程序中。当前的访问控制技术基于安全专家设计的其他安全层。这些额外的安全层未考虑导致业务层与访问控制机制分离的必要业务逻辑。而且,业务层是从商业工具(例如:Hibernate,JDBC,ODBC,LINQ)构建的,而这些商业工具并不是专门为处理安全性而设计的。为了克服这种情况,提出了一些建议。尽管具有相关性,但它们不支持在用于与受保护数据进行交互的运行时值级别上实施访问控制策略。运行时值是关键实体,因为它们在定义访问哪些数据的过程中起着关键作用。在本文中,我们提出了一种用于在业务层级别进行静态检查的常规技术,该技术用于与数据库进行交互并根据已建立的访问控制策略进行运行时值。该技术适用于CRUD(创建,读取,更新和删除)表达式,也适用于对由Select表达式检索的数据执行的操作(更新和插入)。还提供了概念证明。它使用先前开发的访问控制平台,该平台缺少本文的关键问题。收集的结果表明,所提出的方法是一种有效的解决方案,用于在用于与关系数据库中的数据进行交互的运行时值级别上实施访问控制策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号