发明授权
US09043309B2 SQL transformation-based optimization techniques for enforcement of data access control
有权
用于执行数据访问控制的基于SQL变换的优化技术
- 专利标题: SQL transformation-based optimization techniques for enforcement of data access control
- 专利标题(中): 用于执行数据访问控制的基于SQL变换的优化技术
-
申请号: US13488739申请日: 2012-06-05
-
公开(公告)号: US09043309B2公开(公告)日: 2015-05-26
- 发明人: Tanvir Ahmed , Thomas Keefe , Chao Liang , Vikram Pesati
- 申请人: Tanvir Ahmed , Thomas Keefe , Chao Liang , Vikram Pesati
- 申请人地址: US CA Redwood Shores
- 专利权人: ORACLE INTERNATIONAL CORPORATION
- 当前专利权人: ORACLE INTERNATIONAL CORPORATION
- 当前专利权人地址: US CA Redwood Shores
- 代理机构: Hickman Palermo Becker Bingham LLP
- 主分类号: G06F17/30
- IPC分类号: G06F17/30 ; G06F21/62
摘要:
Techniques are provided for a database server to identify a query that comprises an access check operator specifying a data access control policy, and if so, to re-write the query to produce an optimized query execution plan. A first technique rewrites a query comprising an access check operator based on the privileges associated with the database principal requesting the query. The rewritten query exposes the access predicates relevant to the requesting principal to subsequent database optimization processes. A second technique rewrites a query comprising an access check operator that specifies a data security policy that does not include a denied privilege. A third technique rewrites a query that comprises an access check operator specifying one or more database table columns that store row-specific access control lists. The rewritten queries are used to generate a query execution plan that provides for several query execution optimizations.
公开/授权文献
信息查询