摘要:
A system and method for facilitating secure access to database(s) (fig. 1, 120) is provided. The system relates to authorizing discriminatory access (fig. 4, 400) to relational database data (120). More particularly, the invention provides for an innovative technique of defining secured access to rows (fig. 2, 220) in relational database tables (fig. 2, 200) in a way that cannot be spoofed while preserving various optimization (fig. 4, 410) techniques. The invention affords a persistent scheme via providing for a security architecture whereby discriminatory access policies (fig. 3, 300) on persistent entities can be defined and enforced while preserving set based associative query capabilities (700, 710, 714). With respect to one particular implementation of the invention, creation, modification and deletion of access control lists called security descriptors (fig. 4, 130, 300) is provided. The security descriptors (130, 300) can be provisioned independent of rows (220) in tables (200) of the database (120) and can be shared and embody the policy on what permissions are granted (720) to whom when associated with a row (200).
摘要:
Embodiments of the invention are disclosed for establishing single identity/single-sign on (SSO) on a cloud computing platform. In an embodiment, a user is validated to the cloud computing platform, and identifies a domain. After establishing that the user has control of the domain, the cloud computing platform configures a directory service for the domain. The user may then use the directory service on the cloud computing platform to log in to his or her computer, as well as software services hosted on the cloud computing platform.