SYSTEMS AND METHODS FOR FINE GRAINED ACCESS CONTROL OF DATA STORED IN RELATIONAL DATABASES
    1.
    发明公开
    SYSTEMS AND METHODS FOR FINE GRAINED ACCESS CONTROL OF DATA STORED IN RELATIONAL DATABASES 审中-公开
    FOR细粒度访问控制关系数据库系统和存储的方法

    公开(公告)号:EP1616252A2

    公开(公告)日:2006-01-18

    申请号:EP04779289.0

    申请日:2004-07-26

    IPC分类号: G06F7/00

    摘要: A system and method for facilitating secure access to database(s) (fig. 1, 120) is provided. The system relates to authorizing discriminatory access (fig. 4, 400) to relational database data (120). More particularly, the invention provides for an innovative technique of defining secured access to rows (fig. 2, 220) in relational database tables (fig. 2, 200) in a way that cannot be spoofed while preserving various optimization (fig. 4, 410) techniques. The invention affords a persistent scheme via providing for a security architecture whereby discriminatory access policies (fig. 3, 300) on persistent entities can be defined and enforced while preserving set based associative query capabilities (700, 710, 714). With respect to one particular implementation of the invention, creation, modification and deletion of access control lists called security descriptors (fig. 4, 130, 300) is provided. The security descriptors (130, 300) can be provisioned independent of rows (220) in tables (200) of the database (120) and can be shared and embody the policy on what permissions are granted (720) to whom when associated with a row (200).