earticle

논문검색

Bouncer : Policy-Based Fine Grained Access Control in Large Databases

초록

영어

Current access control solutions in databases are based on tables and views. While view access control approach is flexible, it does not scale when the number of users (and therefore necessary views) is large. Consequently, most applications are forced to perform access control enforcement in the application code instead of the database. This approach has numerous disadvantages. We present a novel approach for fine-grained access control in large databases. Our solution combines relational databases with trust management techniques. Trust management systems such as KeyNote and CPOL can be used to evaluate policy rules to determine whether a given query can be performed and which parts of the resulting data can be presented to the user. We present the design and implementation of our system as well as a set of performance experiments based on MySQL database and CPOL policy evaluation engine.

목차

Abstract
 1. Introduction
 2. Related Works
 3. Policy
  3.1. Trust Management
  3.2. CPOL
  3.3. Access Control Model
  3.4. Example Application and Policies
 4. Design and Implementation
  4.1. Security Assumptions
  4.2. Design and Implementation
  4.3. Example Scenario
  4.4 Privacy Leaks
 5. Experiments
  5.1. Experiment Setup
  5.2. Experiment Results
 6. Conclusion and Future Work
  6.1. Privacy Leaks
 References

저자정보

  • Lukasz Opyrchal Miami University, Oxford, OH
  • Jeff Cooper Miami University, Oxford, OH
  • Ryan Poyar Purdue University, West Lafayette, IN
  • Brian Lenahan Miami University, Oxford, OH
  • Daniel Zeinner Miami University, Oxford, OH

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.