Business Policy Modeling and Enforcement in Databases

被引:0
|
作者
Ataullah, Ahmed A. [1 ]
Tompa, Frank Wm. [1 ]
机构
[1] Univ Waterloo, David R Cheriton Sch Comp Sci, Waterloo, ON, Canada
来源
PROCEEDINGS OF THE VLDB ENDOWMENT | 2011年 / 4卷 / 11期
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Database systems are the central information repositories for businesses and are subject to a wide array of policies, rules and requirements. The spectrum of business level constraints implemented within database systems has expanded from classical access control to include auditing, usage control, privacy management, and records retention. The lack of a systematic mechanism of integrating and reasoning about such a diverse set of policies manifested as database level constraints makes corporate policy management a chaotic process. In this paper we propose a general purpose policy modeling and constraint management framework that can integrate numerous aspects of business level requirements within database systems. Our proposed solution relies on a finite state modeling language for business level policies, in which users can declaratively express rules related to the normal workflow of a business process as well as specifying any undesirable states of business objects contained in a database system. The proposed system is then able to translate these policies into low level temporal integrity constraints that prevent policy violations and ensure that business objects and artifacts follow their mandated lifecycles. A formal layer for reasoning allows policy makers to discover unenforceable and conflicting policies, providing the basis to guarantee compliance for a wide array of rules that may need to be enforced on complex business objects stored in relational database systems.
引用
下载
收藏
页码:921 / 931
页数:11
相关论文
共 50 条
  • [21] MODELING AND DATABASES
    BEYNONDAVIES, P
    HUTCHINGS, AR
    EUROPEAN JOURNAL OF OPERATIONAL RESEARCH, 1993, 64 (03) : 327 - 337
  • [22] ONLINE BUSINESS DATABASES AND VIEWDATA
    TAYLOR, KH
    ONLINE REVIEW, 1979, 3 (04): : 420 - 420
  • [23] STATISTICAL AND NUMERIC DATABASES FOR BUSINESS
    OJALA, M
    DATABASE, 1993, 16 (03): : 99 - 101
  • [24] Distribution and integration of databases across law enforcement agencies
    Briceno, R
    NATIONAL AND INTERNATIONAL LAW ENFORCEMENT DATABASES, 1997, 2940 : 118 - 125
  • [25] Policy and enforcement in virtual organizations
    Wasson, G
    Humphrey, M
    FOURTH INTERNATIONAL WORKSHOP ON GRID COMPUTING, PROCEEDINGS, 2003, : 125 - 132
  • [26] A National Policy for Enforcement of Prohibition
    Frankfurter, Felix
    ANNALS OF THE AMERICAN ACADEMY OF POLITICAL AND SOCIAL SCIENCE, 1923, 109 : 193 - 195
  • [27] THE METHODOLOGY OF LAW ENFORCEMENT POLICY
    Kleymenov, Mikhail P.
    Erokhin, Denis, V
    PRAVOPRIMENENIE-LAW ENFORCEMENT REVIEW, 2018, 2 (04): : 5 - 15
  • [28] Policy Enforcement Point Model
    Ben Mustapha, Yosra
    Debar, Herve
    Blanc, Gregory
    INTERNATIONAL CONFERENCE ON SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2014, PT I, 2015, 152 : 278 - 286
  • [29] Environmental policy: Implementation and enforcement
    Jack, B
    JOURNAL OF COMMON MARKET STUDIES, 2003, 41 (04): : 776 - 777
  • [30] Harbormaster: Policy Enforcement for Containers
    Zhang, Mingwei
    Marino, Daniel
    Efstathopoulos, Petros
    2015 IEEE 7TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), 2015, : 355 - 362