ACM Home Page
Please provide us with feedback. Feedback
A flexible authorization mechanism for relational data management systems
Full text PdfPdf (258 KB)
Source ACM Transactions on Information Systems (TOIS) archive
Volume 17 ,  Issue 2  (April 1999) table of contents
Pages: 101 - 140  
Year of Publication: 1999
ISSN:1046-8188
Authors
Elisa Bertino  Univ. di Milano, Milan, Italy
Sushil Jajodia  George Mason Univ., Fairfax, VA
Pierangela Samarati  Univ. di Milano, Milan, Italy
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 14,   Downloads (12 Months): 92,   Citation Count: 25
Additional Information:

abstract   references   cited by   index terms   review   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/306686.306687
What is a DOI?

ABSTRACT

In this article, we present an authorization model that can be used to express a number of discretionary access control policies for relational data management systems. The model permits both positive and negative authorizations and supports exceptions at the same time. The model is flexible in that the users can specify, for each authorization they grant, whether the authorization can allow for exceptions or whether it must be strongly obeyed. It provides authorization management for groups with exceptions at any level of the group hierarchy, and temporary suspension of authorizations. The model supports ownership together with decentralized administration of authorizations. Administrative privileges can also be restricted so that owners retain control over their tables.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

1
 
2
 
3
BERTINO, E., JAJODIA, S., AND SAMARATI, P. 1996b. A flexible authorization mechanism for relational data management systems. Tech. Rep. Computer Science Department, Universit di Milano, Milan, Italy.
 
4
 
5
 
6
BR GGEMANN, H. H. 1992. Rights in an object-oriented environment. In Database Security V, Status and Prospects, C. Landwehr and S. Jajodia, Eds. Elsevier North-Holland, Inc., New York, NY.
 
7
8
 
9
GAGLIARDI, R., LAPIS, G., AND LINDSAY, B. 1989. A flexible and efficient database authorization facility. Tech. Rep. RJ 6826(65360). IBM Almaden Research Center.
 
10
11
 
12
INFORMIX. 1993. Informix-Online #Secure. Security Features User's Guide. Informix Software, Inc.
 
13
 
14
LORETTI, S. 1996. Flexauth system--User manual. Computer Science Department, Universit di Milano, Milan, Italy.
 
15
LUNT, T. F. 1989. Access control policies for database systems. In Database Security II: Status and Prospects, C. E. Landwehr, Ed. North-Holland Publishing Co., Amsterdam, The Netherlands, 41-52.
 
16
LUNT, T. F., DENNING, D. E., SCHELL, R. R., HECKMAN, M., AND SHOCKLY, W. R. 1989. Secure distributed data views. Tech. Rep. Computer Science Laboratory, SRI International, Menlo Park, CA. Volumes 1-4.
 
17
MELTON, J. 1990. ISO/ANSI working draft--Database language sql2. Tech. Rep. ANSI X3H2-90-309. ANSI, New York, NY.
18
19
 
20
SELINGER, P. G. 1990. Authorizations and views. In Distributed Data Bases, I. W. Draffan and F. Pooe, Eds. Cambridge University Press, New York, NY.
21

CITED BY  25


REVIEW

"Eduardo B. Fernandez : Reviewer"

While relational databases are in widespread use and probably will be for a while, most of the work on their theoretical aspects, including security, was done in the 1970s. In other words, relational databases are no longer in the forefront of  more...

Collaborative Colleagues:
Elisa Bertino: colleagues
Sushil Jajodia: colleagues
Pierangela Samarati: colleagues