A fine-grained access control model for relational databases

被引:7
|
作者
Shi, Jie [1 ]
Zhu, Hong [1 ]
机构
[1] Huazhong Univ Sci & Technol, Coll Comp Sci & Technol, Wuhan 430074, Peoples R China
关键词
Fine-grained access control; Database security; Prohibition; Multiple policies;
D O I
10.1631/jzus.C0910466
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Fine-grained access control (FGAC) must be supported by relational databases to satisfy the requirements of privacy preserving and Internet-based applications. Though much work on FGAC models has been conducted, there are still a number of ongoing problems. We propose a new FGAC model which supports the specification of open access control policies as well as closed access control policies in relational databases. The negative authorization is supported, which allows the security administrator to specify what data should not be accessed by certain users. Moreover, multiple policies defined to regulate user access together are also supported. The definition and combination algorithm of multiple policies are thus provided. Finally, we implement the proposed FGAC model as a component of the database management system (DBMS) and evaluate its performance. The performance results show that the proposed model is feasible.
引用
收藏
页码:575 / 586
页数:12
相关论文
共 50 条
  • [2] A fine-grained access control model for relational databases
    Jie Shi
    Hong Zhu
    [J]. Journal of Zhejiang University SCIENCE C, 2010, 11 : 575 - 586
  • [3] DBMask: Fine-Grained Access Control on Encrypted Relational Databases
    Sarfraz, Muhammad I.
    Nabeel, Mohamed
    Cao, Jianneng
    Bertino, Elisa
    [J]. TRANSACTIONS ON DATA PRIVACY, 2016, 9 (03) : 187 - 214
  • [4] Fine-Grained Access Control in Hybrid Relational-XML Databases
    Sasaki, Taketo
    Fukushima, Takuya
    Park, Daeil
    Toyama, Motomichi
    [J]. 2008 THIRD INTERNATIONAL CONFERENCE ON DIGITAL INFORMATION MANAGEMENT, VOLS 1 AND 2, 2008, : 611 - +
  • [5] Fine-grained Access Control to Web Databases
    Roichman, Alex
    Gudes, Ehud
    [J]. SACMAT'07: PROCEEDINGS OF THE 12TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2007, : 31 - 40
  • [6] Towards a fine-grained access control model and mechanisms for semantic databases
    Franzoni, Stefano
    Mazzoleni, Pietro
    Valtolina, Stefano
    Mazzoleni, Pietro
    Bertino, Elisa
    [J]. 2007 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS, 2007, : 993 - +
  • [7] A Fine-Grained Image Access Control Model
    Al Bouna, Bechara
    Chbeir, Richard
    Gabillon, Alban
    Capolsini, Patrick
    [J]. 8TH INTERNATIONAL CONFERENCE ON SIGNAL IMAGE TECHNOLOGY & INTERNET BASED SYSTEMS (SITIS 2012), 2012, : 603 - 612
  • [8] OBSERVATION-BASED FINE GRAINED ACCESS CONTROL FOR RELATIONAL DATABASES
    Halder, Raju
    Cortesi, Agostino
    [J]. ICSOFT 2010: PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON SOFTWARE AND DATA TECHNOLOGIES, VOL 1, 2010, : 254 - 265
  • [9] Design and Application of Fine-Grained Access Control Model
    Xie, Xuelian
    Yang, Haibo
    Li, Lanyou
    [J]. NETWORK COMPUTING AND INFORMATION SECURITY, 2012, 345 : 23 - +
  • [10] Fine-grained Access Control Model Based on RBAC
    Gao, Lei
    Pan, Shulin
    [J]. AUTOMATION EQUIPMENT AND SYSTEMS, PTS 1-4, 2012, 468-471 : 1667 - +