首页>
外国专利>
DATABASE ACCESS-CONTROL POLICY ENFORCEMENT USING REVERSE QUERIES
DATABASE ACCESS-CONTROL POLICY ENFORCEMENT USING REVERSE QUERIES
展开▼
机译:使用逆向查询执行数据库访问控制策略
展开▼
页面导航
摘要
著录项
相似文献
摘要
A method of providing access control to a relational database (14) accessible from a user interface (10) is implemented at a policy enforcement point (12), which is located between the database and the user interface and comprises the steps of: (i) intercepting a database query from a user; (ii) assigning attribute values on the basis of a target table or target column in the query, a construct type in the query, or the user or environment; (iii) partially evaluating an access-control policy (P) defined in terms of said attributes, by constructing a partial policy decision request containing the attribute values assigned in step ii) and evaluating the AC policy for this, whereby a simplified policy (P') is obtained; (iv) deriving an access condition, for which the simplified policy permit access; and (v) amending the database query by imposing said access condition and transmitting the amended query (Q') to the database.
展开▼