首页> 外国专利> FINE-GRAINED DATABASE ACCESS-CONTROL POLICY ENFORCEMENT USING REVERSE QUERIES

FINE-GRAINED DATABASE ACCESS-CONTROL POLICY ENFORCEMENT USING REVERSE QUERIES

机译:使用反向查询执行精细的数据库访问控制策略

摘要

A method of providing access control to a database accessible from a user interface is implemented at a policy enforcement point, which is located between the database and the user interface and includes the steps of: (i) intercepting a database query; (ii) assigning attribute values on the basis of a target table or target column in the query, a construct type in the query, or the user or environment; (iii) partially evaluating an access-control policy defined in terms of said attributes, by constructing a partial policy decision request containing the attribute values assigned in step ii) and evaluating the access-control policy for this, whereby a simplified policy is obtained; (iv) deriving an access condition, for which the simplified policy permits access; and (v) amending the database query by imposing said access condition and transmitting the amended query to the database.
机译:在位于数据库和用户界面之间的策略执行点实现一种提供对从用户界面可访问的数据库的访问控制的方法,该策略执行点包括以下步骤:(i)拦截数据库查询; (ii)根据查询中的目标表或目标列,查询中的构造类型或用户或环境来分配属性值; (iii)通过构造包含在步骤ii)中分配的属性值的部分策略决策请求并评估该访问控制策略,来部分评估根据所述属性定义的访问控制策略,从而获得简化的策略; (iv)得出访问条件,简化的策略允许访问; (v)通过施加所述访问条件来修改数据库查询,并将修改后的查询发送到数据库。

著录项

  • 公开/公告号US2017323029A1

    专利类型

  • 公开/公告日2017-11-09

    原文格式PDF

  • 申请/专利权人 AXIOMATICS AB;

    申请/专利号US201715488794

  • 发明设计人 ERIK RISSANEN;

    申请日2017-04-17

  • 分类号G06F17/30;G06F21/62;G06F17/30;

  • 国家 US

  • 入库时间 2022-08-21 13:48:37

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号