A Temporal Access Control Mechanism for Database Systems

A Temporal Access Control Mechanism for Database Systems
复制标题

数据库系统的时态访问控制机制

DOI:
10.1109/69.485637
复制
发表时间:
1996
期刊:
IEEE Trans. Knowl. Data Eng.
影响因子:
--
通讯作者:
P. Samarati
P. Samarati
中科院分区:
--
文献类型:
--
作者:
E. Bertino;C. Bettini;E. Ferrari;P. Samarati

文献摘要

被引文献

相似文献

本文提出了一种自主访问控制模型,其中授权包含有效性的时间间隔。当关联的时间间隔到期时,授权将自动撤销。所提出的模型提供了从明确指定的授权中自动派生新授权的规则。支持正授权和负授权。提出了这些概念的正式定义,以及作为通用逻辑程序的子句的授权和派生规则的语义解释。讨论了因存在负面授权而产生的问题。我们还允许规则中的否定:可以在没有其他授权的情况下派生新的授权。此类规则的存在可能会导致生成不同的授权集,具体取决于评估顺序。提出了一种基于在授权和派生规则之间建立排序的方法,该方法保证了一组唯一的有效授权。此外,我们给出了一种算法来检测是否可以为给定的一组授权和规则建立这样的排序。本文还介绍了添加、删除或修改授权和派生规则的管理操作,并解决了与这些操作相关的效率问题。提出了一种物化方法,允许有效地执行访问控制。
The paper presents a discretionary access control model in which authorizations contain temporal intervals of validity. An authorization is automatically revoked when the associated temporal interval expires. The proposed model provides rules for the automatic derivation of new authorizations from those explicitly specified. Both positive and negative authorizations are supported. A formal definition of those concepts is presented, together with the semantic interpretation of authorizations and derivation rules as clauses of a general logic program. Issues deriving from the presence of negative authorizations are discussed. We also allow negation in rules: it is possible to derive new authorizations on the basis of the absence of other authorizations. The presence of this type of rule may lead to the generation of different sets of authorizations, depending on the evaluation order. An approach is presented, based on establishing an ordering among authorizations and derivation rules, which guarantees a unique set of valid authorizations. Moreover, we give an algorithm detecting whether such an ordering can be established for a given set of authorizations and rules. Administrative operations for adding, removing, or modifying authorizations and derivation rules are presented and efficiency issues related to these operations are also tackled in the paper. A materialization approach is proposed, allowing to efficiently perform access control.