A flexible authorization mechanism for relational data management systems

被引:54
作者
Bertino, E [1 ]
Jajodia, S
Samarati, P
机构
[1] Univ Milan, Dipartimento Sci Informaz, I-20135 Milan, Italy
[2] George Mason Univ, Dept Informat & Software Engn, Fairfax, VA 22030 USA
[3] Univ Milan, Dipartimento Sci Informaz, I-26013 Crema, Italy
关键词
security; theory; access control mechanism; access control policy; authorization; data management system; relational database; group management support;
D O I
10.1145/306686.306687
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this article, we present an authorization model that can be used to express a number of discretionary access control policies for relational data management systems. The model permits both positive and negative authorizations and supports exceptions at the same time. The model is flexible in that the users can specify, for each authorization they grant, whether the authorization can allow for exceptions or whether it must be strongly obeyed. It provides authorization management for groups with exceptions at any level of the group hierarchy, and temporary suspension of authorizations. The model supports ownership together with decentralized administration of authorizations. Administrative privileges can also be restricted so that owners retain control over their tables.
引用
收藏
页码:101 / 140
页数:40
相关论文
共 21 条
[1]   A CALCULUS FOR ACCESS-CONTROL IN DISTRIBUTED SYSTEMS [J].
ABADI, M ;
BURROWS, M ;
LAMPSON, B ;
PLOTKIN, G .
ACM TRANSACTIONS ON PROGRAMMING LANGUAGES AND SYSTEMS, 1993, 15 (04) :706-734
[2]   An extended authorization model for relational databases [J].
Bertino, E ;
Samarati, P ;
Jajodia, S .
IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 1997, 9 (01) :85-101
[3]  
BERTINO E, 1996, P IEEE S SEC PRIV OA
[4]  
Bertino E., IEEE T KNOWL DATA EN, V8, P1
[5]  
BERTINO E, 1996, FLEXIBLE AUTHORIZATI
[6]  
BRUGGEMANN HH, 1992, DATABASE SECURITY, V5
[7]  
CASTANO S, 1995, DATABASE SECURITY
[8]  
Fagin R., 1978, ACM Transactions on Database Systems, V3, P310, DOI 10.1145/320263.320288
[9]  
GAGLIARDI R, 1989, 682665360 RJ IBM ALM
[10]  
GALOZ N, 1993, P INT C VER LARG DAT