ACM Home Page
Please provide us with feedback. Feedback
Label-based access control (LBAC) in DB2 LUW
Source PST; Vol. 380 archive
Proceedings of the 2006 International Conference on Privacy, Security and Trust: Bridge the Gap Between PST Technologies and Business Services table of contents
Markham, Ontario, Canada
SESSION: Industry keynotes table of contents
Article No. 7  
Year of Publication: 2006
ISBN:1-59593-604-1
Author
Sponsor
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): n/a,   Downloads (12 Months): n/a,   Citation Count: 0
Additional Information:

abstract  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1501434.1501443
What is a DOI?

ABSTRACT

data at the row and/or column level based on security labels. Unlike traditional implementations of mandatory access control (e.g., Multilevel Security), the DB2 LBAC capability allows you to tailor the security label definition to best suit your application specific needs. In DB2 LBAC, a security label does not have to be a rigid structure made up of two components (level and compartments). DB2 LBAC allows you to construct the security label type that best suits your application needs from a predefined set of security label components. DB2 then chooses and applies the appropriate access control rules based on the types of the security label components. DB2 LBAC integrates well with other DB2 capabilities and can be combined with such capabilities to offer an even stronger security. For example, you can combine LBAC with any of the data partitioning capabilities available in DB2 such as Multi-Dimensional Clustering (MDC), Data Partitioning Facility (DPF), or table partitioning to increase security by having data from different security levels stored on different data partitions (e.g., the most secure data on the most secure partition). You can also combine LBAC with XML to provide document level access control based on security labels.