Efficiently Supporting Attribute-Based Access Control in Relational Databases

被引:0
|
作者
Meena, Gaurav [1 ]
Paul, Proteet [1 ]
Sural, Shamik [1 ]
机构
[1] Indian Inst Technol Kharagpur, Kharagpur, W Bengal, India
关键词
Relational databases; SQL; Access Control; ABAC; MySQL; Policy Enforcement;
D O I
10.1109/TPS-ISA58951.2023.00037
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
While Attribute-Based Access Control (ABAC) is increasingly becoming popular as a topic of research, it is yet to get traction in real applications. One of the reasons for this gap is that unlike Role-Based Access Control, which got support both from the software developers as well as the database community, ABAC is still not supported in relational databases. In this paper, we propose a comprehensive extension to SQL for attribute-based access control in relational databases covering all kinds of database objects like tables, views, stored procedures and triggers. The different types of ABAC attributes including subject, object as well as environmental attributes, are also supported in the proposed SQL extension. Further, we show how such an ABAC extension can be embedded in one of the most popular open source relational databases, namely MySQL. Towards this, we appropriately augment the source code of MySQL with an efficient method for ABAC policy enforcement. The ABAC augmented MySQL source code is being shared for reproducibility of our results, and also for any potential user to install this version and work with it. Findings from an extensive set of experiments establish the feasibility of our approach.
引用
收藏
页码:230 / 239
页数:10
相关论文
共 50 条
  • [1] Efficiently Supporting Attribute-Based Access Control in Linux
    Varshith, H. O. Sai
    Sural, Shamik
    Vaidya, Jaideep
    Atluri, Vijayalakshmi
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 2012 - 2026
  • [2] Attribute-Based Access Control for NoSQL Databases
    Gupta, Eeshan
    Sural, Shamik
    Vaidya, Jaideep
    Atluri, Vijayalakshmi
    [J]. PROCEEDINGS OF THE ELEVENTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY (CODASPY '21), 2021, : 317 - 319
  • [3] Supporting attribute-based access control with ontologies
    Priebe, Torsten
    Dobmeier, Wolfgang
    Kamprath, Nora
    [J]. FIRST INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, PROCEEDINGS, 2006, : 465 - +
  • [4] Enabling Attribute-Based Access Control in NoSQL Databases
    Gupta, Eeshan
    Sural, Shamik
    Vaidya, Jaideep
    Atluri, Vijayalakshmi
    [J]. IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTING, 2023, 11 (01) : 208 - 223
  • [5] Efficiently Attribute-Based Access Control for Mobile Cloud Storage System
    Lv, Zhiquan
    Chi, Jialin
    Zhang, Min
    Feng, Dengguo
    [J]. 2014 IEEE 13TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM), 2014, : 292 - 299
  • [6] Attribute-Based Access Control
    Hu, Vincent C.
    Kuhn, D. Richard
    Ferraiolo, David F.
    [J]. COMPUTER, 2015, 48 (02) : 85 - 88
  • [7] Towards Supporting Attribute-Based Access Control in Hyperledger Fabric Blockchain
    Pericherla, Amshumaan
    Paul, Proteet
    Sural, Shamik
    Vaidya, Jaideep
    Atluri, Vijay
    [J]. ICT SYSTEMS SECURITY AND PRIVACY PROTECTION (SEC 2022), 2022, 648 : 360 - 376
  • [8] Supporting attribute-based access control in authorization and authentication infrastructures with ontologies
    Priebe, Torsten
    Dobmeier, Wolfgang
    Schläger, Christian
    Kamprath, Nora
    [J]. Journal of Software, 2007, 2 (01) : 27 - 38
  • [9] Using attribute-based access control to enable attribute-based messaging
    Bobba, Rakesh
    Fatemieh, Omid
    Khan, Fariba
    Gunter, Carl A.
    Khurana, Himanshu
    [J]. 22ND ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2006, : 403 - +
  • [10] ABSAC: Attribute-Based Access Control Model Supporting Anonymous Access for Smart Cities
    Zhang, Runnan
    Liu, Gang
    Li, Shancang
    Wei, Yongheng
    Wang, Quan
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2021, 2021