An extended authorization model for relational databases

被引:47
作者
Bertino, E
Samarati, P
Jajodia, S
机构
[1] GEORGE MASON UNIV,CTR SECURE INFORMAT SYST,FAIRFAX,VA 22030
[2] GEORGE MASON UNIV,DEPT INFORMAT & SOFTWARE SYST ENGN,FAIRFAX,VA 22030
基金
美国国家科学基金会;
关键词
database systems; relational database; access control; authorization; security; protection; privacy; revocation of authorizations;
D O I
10.1109/69.567051
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
We propose two extensions to the authorization model for relational databases defined originally by Griffiths and Wade. The first extension concerns a new type of revoke operation, called noncascading revoke operation. The original model contains a single, cascading revoke operation, meaning that when a privilege is revoked from a user, a recursive revocation takes place that deletes all authorizations granted by this user that do not have other supporting authorizations. The new type of revocation avoids the recursive revocation of authorizations. The second extension concerns negative authorization which permits specification of explicit denial for a user to access an object under a particular mode. We also address the management of views and groups with respect to the proposed extensions.
引用
收藏
页码:85 / 101
页数:17
相关论文
共 25 条
[1]  
Astrahan M. M., 1976, ACM Transactions on Database Systems, V1, P97, DOI 10.1145/320455.320457
[2]  
Baldwin R. W., 1990, Proceedings. 1990 IEEE Computer Society Symposium on Research in Security and Privacy (Cat. No.90CH2884-5), P116, DOI 10.1109/RISP.1990.63844
[3]   UPDATE SEMANTICS OF RELATIONAL VIEWS [J].
BANCILHON, F ;
SPYRATOS, N .
ACM TRANSACTIONS ON DATABASE SYSTEMS, 1981, 6 (04) :557-575
[4]  
BERTINO E, 1988, LECT NOTES COMPUT SC, V303, P155
[5]  
BERTINO E, 1994, P 2 ACM C COMP COMM, P126
[6]  
BERTINO E, 1994, EXTENDED AUTHORIZATI, P1
[7]   UPDATE AND RETRIEVAL IN A RELATIONAL DATABASE THROUGH A UNIVERSAL SCHEMA INTERFACE [J].
BROSDA, V ;
VOSSEN, G .
ACM TRANSACTIONS ON DATABASE SYSTEMS, 1988, 13 (04) :449-485
[8]   A HISTORY AND EVALUATION OF SYSTEM-R [J].
CHAMBERLIN, DD ;
ASTRAHAN, MM ;
BLASGEN, MW ;
GRAY, JN ;
KING, WF ;
LINDSAY, BG ;
LORIE, R ;
MEHL, JW ;
PRICE, TG ;
PUTZOLU, F ;
SELINGER, PG ;
SCHKOLNICK, M ;
SLUTZ, DR ;
TRAIGER, IL ;
WADE, BW ;
YOST, RA .
COMMUNICATIONS OF THE ACM, 1981, 24 (10) :632-646
[9]   UPDATES OF RELATIONAL VIEWS [J].
COSMADAKIS, SS ;
PAPADIMITRIOU, CH .
JOURNAL OF THE ACM, 1984, 31 (04) :742-760
[10]  
Department of Defense, 1985, 520028 DOD