首页> 外国专利> Database fine-grained access control employing hierarchical item level entitlement

Database fine-grained access control employing hierarchical item level entitlement

机译:采用分层项级别权限的数据库细粒度访问控制

摘要

A database query is received 300, a user associated with the query determined and an entitlement entry associated with the user - created by applying an entitlement rule associated with the user to a chasing rule - obtained 302. The entitlement entry may be obtained from an entitlement detail table populated by an entitlement engine. The entitlement rule may define a row in a table to which the user has access and operations the user may perform on data in the row, e.g. select, update, delete, insert. The chasing rule may define a hierarchy of tables, including a user-accessible table, and the order in which the hierarchy is traversed. An entitlement predicate for a data view query is determined 304 using the entitlement entry, the data view query including the entitlement predicate and being associated with the query. The data view query is executed 306, the user being entitled to view the data which is thus presented 308, 310. The data may itself be entitled by association with an entry in an entitleable table.
机译:接收302数据库查询,确定与查询相关联的用户,以及通过将与用户相关联的权利规则应用于跟踪规则而创建的与用户相关联的权利条目,获得302。可以从权利中获得权利条目。详细信息表由权利引擎填充。权利规则可以定义用户有权访问的表中的行以及用户可以对该行中的数据执行的操作,例如,选择,更新,删除,插入。追踪规则可以定义表的层次结构,包括用户可访问的表,以及遍历该层次结构的顺序。使用授权条目来确定304用于数据视图查询的授权谓词,该数据视图查询包括授权谓词并且与查询相关联。数据视图查询被执行306,用户被授权查看由此呈现的数据308、310。数据本身可以通过与可授权表中的条目的关联而被授权。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号