Effectively and Efficiently Selecting Access Control Rules on Materialized Views over Relational Databases

被引:6
|
作者
Cuzzocrea, Alfredo [1 ,2 ]
Hacid, Mohand-Said [3 ,4 ]
Grillo, Nicola [5 ]
机构
[1] ICAR CNR, Arcavacata Di Rende, Italy
[2] Univ Calabria, Arcavacata Di Rende, Italy
[3] Univ C Bernard Lyon 1, Lyon, France
[4] LIRIS, Ecully, France
[5] Univ Calabria, DEIS Dept, Arcavacata Di Rende, Italy
关键词
Access Control Rules over Relational Databases; Security Policies over Relational Databases; Query Rewriting Techniques for Relational Database Security;
D O I
10.1145/1866480.1866512
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A novel framework for effectively and efficiently selecting fine-grained access control rules from a target relational database to the set of materialized views defined on such a database is presented and experimentally assessed in this paper, along with the main algorithm implementing the focal selection task, called VSP-Bucket. The proposed security framework introduces a number of research innovations, ranging from a novel Datalog-based syntax, and related semantics, aimed at modeling and expressing access control rules over relational databases to algorithm VSP-Bucket itself, which is a meaningful adaptation of a well-know view-based query re-writing algorithm for query optimization purposes. Our framework exposes a high flexibility, due to the fact it allows several classes of access control rules to be expressed and handled on top of large relational databases, and, at the same, it introduces high effectiveness and efficiency, as demonstrated by our comprehensive experimental evaluation and analysis of performance and scalability of algorithm VSP-Bucket.
引用
收藏
页码:225 / 235
页数:11
相关论文
共 29 条
  • [21] DBMask: Fine-Grained Access Control on Encrypted Relational Databases
    Sarfraz, Muhammad I.
    Nabeel, Mohamed
    Cao, Jianneng
    Bertino, Elisa
    TRANSACTIONS ON DATA PRIVACY, 2016, 9 (03) : 187 - 214
  • [22] OBSERVATION-BASED FINE GRAINED ACCESS CONTROL FOR RELATIONAL DATABASES
    Halder, Raju
    Cortesi, Agostino
    ICSOFT 2010: PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON SOFTWARE AND DATA TECHNOLOGIES, VOL 1, 2010, : 254 - 265
  • [23] On the interaction between role-based access control and relational databases
    Osborn, SL
    Reid, LK
    Wesson, GJ
    DATABASE SECURITY VOLUME X - STATUS AND PROSPECTS, 1997, : 275 - 287
  • [24] Reasoning on Incompleteness of Spatial Information for Effectively and Efficiently Answering Range Queries over Incomplete Spatial Databases
    Cuzzocrea, Alfredo
    Nucita, Andrea
    FLEXIBLE QUERY ANSWERING SYSTEMS: 8TH INTERNATIONAL CONFERENCE, FQAS 2009, 2009, 5822 : 37 - 52
  • [25] Updating XML views published over relational databases: Towards the existence of a correct update mapping
    Wang, Ling
    Rundensteiner, Elke A.
    Mani, Murali
    DATA & KNOWLEDGE ENGINEERING, 2006, 58 (03) : 263 - 298
  • [26] Fine-Grained Access Control in Hybrid Relational-XML Databases
    Sasaki, Taketo
    Fukushima, Takuya
    Park, Daeil
    Toyama, Motomichi
    2008 THIRD INTERNATIONAL CONFERENCE ON DIGITAL INFORMATION MANAGEMENT, VOLS 1 AND 2, 2008, : 611 - +
  • [27] Access control in very loosely structured data model using relational databases
    Pan, Ying
    Tang, Yong
    Liu, Hai
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2012, 40 (03): : 600 - 606
  • [28] Spatial views and LOD-based access control in VRML-object databases
    Kamiura, M
    Oiso, H
    Tajima, K
    Tanaka, K
    WORLDWIDE COMPUTING AND ITS APPLICATIONS, 1997, 1274 : 210 - 225
  • [29] ReLOG: A Unified Framework for Relationship-Based Access Control over Graph Databases
    Clark, Stanley
    Yakovets, Nikolay
    Fletcher, George
    Zannone, Nicola
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXXVI, DBSEC 2022, 2022, 13383 : 303 - 315