Invention Grant
US08930403B2 Fine-grained relational database access-control policy enforcement using reverse queries
有权
使用反向查询的细粒度关系数据库访问控制策略实施
- Patent Title: Fine-grained relational database access-control policy enforcement using reverse queries
- Patent Title (中): 使用反向查询的细粒度关系数据库访问控制策略实施
-
Application No.: US14335252Application Date: 2014-07-18
-
Publication No.: US08930403B2Publication Date: 2015-01-06
- Inventor: Erik Rissanen
- Applicant: Axiomatics AB
- Applicant Address: SE Stockholm
- Assignee: Axiomatics AB
- Current Assignee: Axiomatics AB
- Current Assignee Address: SE Stockholm
- Agency: Buchanan Ingersoll & Rooney P.C.
- Priority: EP11164924 20110505
- Main IPC: G06F17/30
- IPC: G06F17/30 ; G06F21/62

Abstract:
A method of providing access control to a relational database accessible from a user interface is implemented at a policy enforcement point, which is located between the database and the user interface and includes the steps of: (i) intercepting a database query from a user; (ii) assigning attribute values on the basis of a target table or target column in the query, a construct type in the query, or the user or environment; (iii) partially evaluating an access-control policy defined in terms of said attributes, by constructing a partial policy decision request containing the attribute values assigned in step ii) and evaluating the AC policy for this, whereby a simplified policy is obtained; (iv) deriving an access condition, for which the simplified policy permit access; and (v) amending the database query by imposing said access condition and transmitting the amended query to the database.
Public/Granted literature
- US20140330856A1 FINE-GRAINED RELATIONAL DATABASE ACCESS-CONTROL POLICY ENFORCEMENT USING REVERSE QUERIES Public/Granted day:2014-11-06
Information query