Flexible security policies in SQL

  • Authors:
  • Steve Barker;Arnon Rosenthal

  • Affiliations:
  • Cavendish School of Computer Science, University of Westminster, London, UK;The MITRE Corporation, 202 Burlington Road, Bedford, MA

  • Venue:
  • Das'01 Proceedings of the fifteenth annual working conference on Database and application security
  • Year:
  • 2001

Quantified Score

Hi-index 0.02

Visualization

Abstract

We show how a wide variety of role-based access control policies may be formally specified in the stratified subset of clause form logic. We then show how these formal specifications may be automatically translated into a small subset of SQL to be used to seamlessly protect an SQL database from unauthorized read and update requests made by authenticated users. We demonstrate the power of our approach by showing how a variety of access control policies can be represented.