A flexible authorization mechanism for relational data management systems
- 1 April 1999
- journal article
- Published by Association for Computing Machinery (ACM) in ACM Transactions on Information Systems
- Vol. 17 (2) , 101-140
- https://doi.org/10.1145/306686.306687
Abstract
In this article, we present an authorization model that can be used to express a number of discretionary access control policies for relational data management systems. The model permits both positive and negative authorizations and supports exceptions at the same time. The model is flexible in that the users can specify, for each authorization they grant, whether the authorization can allow for exceptions or whether it must be strongly obeyed. It provides authorization management for groups with exceptions at any level of the group hierarchy, and temporary suspension of authorizations. The model supports ownership together with decentralized administration of authorizations. Administrative privileges can also be restricted so that owners retain control over their tables.Keywords
This publication has 7 references indexed in Scilit:
- An extended authorization model for relational databasesIEEE Transactions on Knowledge and Data Engineering, 1997
- A temporal access control mechanism for database systemsIEEE Transactions on Knowledge and Data Engineering, 1996
- A calculus for access control in distributed systemsACM Transactions on Programming Languages and Systems, 1993
- A model of authorization for next-generation database systemsACM Transactions on Database Systems, 1991
- Integrating security in a large distributed systemACM Transactions on Computer Systems, 1989
- On an authorization mechanismACM Transactions on Database Systems, 1978
- An authorization mechanism for a relational database systemACM Transactions on Database Systems, 1976