首页> 外国专利> DATABASE ACCESS-CONTROL POLICY ENFORCEMENT USING REVERSE QUERIES

DATABASE ACCESS-CONTROL POLICY ENFORCEMENT USING REVERSE QUERIES

机译:使用逆向查询执行数据库访问控制策略

摘要

A method of providing access control to a relational database (14) accessible from a user interface (10) is implemented at a policy enforcement point (12), which is located between the database and the user interface and comprises the steps of: (i) intercepting a database query from a user; (ii) assigning attribute values on the basis of a target table or target column in the query, a construct type in the query, or the user or environment; (iii) partially evaluating an access-control policy (P) defined in terms of said attributes, by constructing a partial policy decision request containing the attribute values assigned in step ii) and evaluating the AC policy for this, whereby a simplified policy (P') is obtained; (iv) deriving an access condition, for which the simplified policy permit access; and (v) amending the database query by imposing said access condition and transmitting the amended query (Q') to the database.
机译:在位于数据库和用户界面之间的策略执行点(12)处实现一种提供对可从用户界面(10)访问的关系数据库(14)的访问控制的方法,该策略执行点位于数据库和用户界面之间,并且包括以下步骤: )拦截来自用户的数据库查询; (ii)根据查询中的目标表或目标列,查询中的构造类型或用户或环境来分配属性值; (iii)通过构造包含步骤ii)中分配的属性值的部分策略决策请求并为此评估AC策略,从而部分评估根据所述属性定义的访问控制策略(P),从而简化策略(P ')已获得; (iv)得出访问条件,简化策略允许对其进行访问; (v)通过施加所述访问条件来修改数据库查询,并将修改后的查询(Q')发送到数据库。

著录项

  • 公开/公告号EP3299989B1

    专利类型

  • 公开/公告日2019-04-10

    原文格式PDF

  • 申请/专利权人 AXIOMATICS AB;

    申请/专利号EP20170181730

  • 发明设计人 RISSANEN ERIK;

    申请日2012-05-04

  • 分类号G06F21/60;G06F21/62;G06F17/30;

  • 国家 EP

  • 入库时间 2022-08-21 12:30:06

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号