Controlling aggregation in Distributed Object systems: A graph-based approach

被引:2
|
作者
Tari, Z [1 ]
Fry, A [1 ]
机构
[1] RMIT Univ, Sch Comp Sci & Informat Technol, Melbourne, Vic 3001, Australia
关键词
Access Control; data aggregation; inference; distributed databases; federated databases; CORBA;
D O I
10.1109/71.970557
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The Distributed Object Kernel is a federated database system providing a set of services which allow cooperative processing across different databases. The focus of this paper is the design of a DOK security service that provides for enforcing both local security policies, related to the security of local autonomous databases, and federated security policies, governing access to data aggregates composed of data from multiple distributed databases. We propose Global Access Control, an extended access control mechanism enabling a uniform expression of heterogeneous security information. Mappings from existing Mandatory and Discretionary Access Controls are described. To permit the control of data aggregation, the derivation of unauthorized information from authorized data, our security framework provides a logic-based language, the Federated Logic Language (FELL), which can describe constraints on both single and multiple states of the federation. To enforce constraints, FELL statements are mapped to state transition graphs which model the different subcomputations required to check the aggregation constraints, Graph aggregation operations are proposed for building compound state transition graphs for complex constraints. To monitor aggregation constraints, two marking techniques, called Linear Marking Technique and Zigzag Marking Technique, are proposed. Finally, we describe a three-layer DOK logical secure architecture enabling the implementation of the different security agents. This includes a Coordination layer, a Task layer, and a Database layer. Each contains specialized agents that enforce a different part of the federated security policy, Coordination is performed by the DOK Manager, enforcing security is performed by a specialized Constraint Manager agent, and the database functions are implemented by user and data agents.
引用
收藏
页码:1236 / 1255
页数:20
相关论文
共 50 条
  • [1] Graph-Based Modelling with Distributed Systems
    Preisig, Heinz A.
    Elve, Arne Tobias
    28TH EUROPEAN SYMPOSIUM ON COMPUTER AIDED PROCESS ENGINEERING, 2018, 43 : 241 - 246
  • [2] A Backmapping Approach for Graph-based Object Tracking
    Paixao, Thiago Meireles
    Graciano, Ana Beatriz V.
    Cesar, Roberto M., Jr.
    Hirata, Roberto, Jr.
    SIBGRAPI 2008: XXI BRAZILIAN SYMPOSIUM ON COMPUTER GRAPHICS AND IMAGE PROCESSING, 2008, : 45 - 52
  • [3] A Graph-Based Feature Combination Approach to Object Tracking
    Quang Anh Nguyen
    Robles-Kelly, Antonio
    Zhou, Jun
    COMPUTER VISION - ACCV 2009, PT II, 2010, 5995 : 224 - 235
  • [4] Object localization in procedural programs: a graph-based approach
    Department of Computer Science, Louisiana State University, Baton Rouge, LA 70803, United States
    Journal of Software Maintenance, 2000, 12 (05): : 305 - 323
  • [5] Object localization in procedural programs: a graph-based approach
    Carver, DL
    Valasareddi, R
    JOURNAL OF SOFTWARE MAINTENANCE-RESEARCH AND PRACTICE, 2000, 12 (05): : 305 - 323
  • [6] Graph-based object tracking
    Gomila, C
    Meyer, F
    2003 INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, VOL 2, PROCEEDINGS, 2003, : 41 - 44
  • [7] Graph-based rank aggregation: a deep-learning approach
    Keyhanipour, Amir Hosein
    INTERNATIONAL JOURNAL OF WEB INFORMATION SYSTEMS, 2025, 21 (01) : 54 - 76
  • [8] Complex object-oriented queries: A graph-based approach
    Taniar, D
    Rahayu, JW
    INTERNATIONAL SOCIETY FOR COMPUTERS AND THEIR APPLICATIONS 13TH INTERNATIONAL CONFERENCE ON COMPUTERS AND THEIR APPLICATIONS, 1998, : 194 - 197
  • [9] Graph-based model for object recognition
    Ton, Pham Trong
    Lux, Augustin
    Hai, Tran Thi Thanh
    ICTACS 2006: First International Conference on Theories and Applications of Computer Science 2006, 2007, : 65 - 78
  • [10] Graph-based particular object discovery
    Simeoni, Oriane
    Iscen, Ahmet
    Tolias, Giorgos
    Avrithis, Yannis
    Chum, Ondrej
    MACHINE VISION AND APPLICATIONS, 2019, 30 (02) : 243 - 254