发明名称 Fine-grained relational database access-control policy enforcement using reverse queries
摘要 A method of providing access control to a relational database (14) accessible from a user interface (10) is implemented at a policy enforcement point (12), which is located between the database and the user interface and comprises the steps of: (i) intercepting a database query from a user; (ii) assigning attribute values on the basis of a target table or target column in the query, a construct type in the query, or the user or environment; (iii) partially evaluating an access-control policy (P) defined in terms of said attributes, by constructing a partial policy decision request containing the attribute values assigned in step ii) and evaluating the AC policy for this, whereby a simplified policy (P') is obtained; (iv) deriving an access condition, for which the simplified policy permit access; and (v) amending the database query by imposing said access condition and transmitting the amended query (Q') to the database.
申请公布号 EP2521066(A1) 申请公布日期 2012.11.07
申请号 EP20110164924 申请日期 2011.05.05
申请人 AXIOMATICS AB 发明人 RISSANEN, ERIK
分类号 G06F21/24;G06F17/30 主分类号 G06F21/24
代理机构 代理人
主权项
地址