谷歌浏览器插件
订阅小程序
在清言上使用

Model-based Characterization of fine-grained Access Control Authorization for SQL Queries.

JOURNAL OF OBJECT TECHNOLOGY(2020)

引用 2|浏览2
暂无评分
摘要
We propose a model-based characterization of fine-grained access control (FGAC) authorization for SQL queries. More specifically, we define a predicate AuthQuery() that represents whether a user is authorized by an FGAC-policy to execute a SQL query on a database. It is characteristic of FGAC-policies that access control decisions depend on dynamic information, namely whether the current state of the system satisfies some "authorization constraints". In our proposal, FGAC-policies are modeled using a dialect of SecureUML, and authorization constraints are specified using the Object Constraint Language (OCL). To illustrate our definition of the predicate AuthQuery(), we provide examples of authorization decisions for different SQL queries, attempted by different users, in different scenarios, and with respect to different FGAC-policies. Interestingly, the availability of mappings from OCL to SQL opens up the possibility of implementing AuthQuery() within the database and, consequently, of enforcing FGAC-policies following a model-driven approach.
更多
查看译文
关键词
Model-driven security,SQL,Fine-grained access control,Authorization,SecureUML,OCL
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要