A Unified Model for Security and Integrity in Relational Databases
نویسنده
چکیده
T h e issues of database security and integrity are tightly related. Security mechanisms and integrity mechanisms are both concerned with protection of information, and both involve management of meta-information and procedures for screening transactions. Yet in database systems these tasks are entirely separate. In this paper we describe a unified model that accommodates both security and integrity, with all protective restrictions stated in terms of database views. These protective restrictions are treated as knowledge, from which transaction screening procedures infer the restrictions tha t apply to individual transactions. A transaction may be allowed or denied in its entirety, or specific non-violating subtransactions may be identified. This process is an application of the view inference problem, to which we offer two alternative solutions. We then show how users can exploit information made available by the integrity mechanism to bypass the security mechanism, and discuss how such security breaches can be avoided. Finally, we show how the model can accommodate a broader concept of integrity that was introduced recently.
منابع مشابه
Fuzzy multi-criteria selection procedures in choosing data source
Technology assessment and selection has a substantial impact on organizations procedures in regards to technology transfer. Technological decisions are usually made by a group of experts, and whereby integrity of these viewpoints to a single decision can be quite complex. Today, operational databases and data warehouses exist to manage and organize data with specific features and henceforth, th...
متن کامل3.3 Validity Checking
14 the multilevel security constraints that precisely characterize the validity of mul-tilevel relational databases. Our model-theoretic semantics is consistent with, and extends, the Bell-LaPadula model. Compared with existing approaches, our model-theoretic semantics maximizes believability without compromising integrity or introducing ambiguity. Contrary to the claim that integrity and secre...
متن کاملIntegrity in Multilevel Secure Database Management Systems
Integrity is usually considered to be at odds with security in multilevel databases. Integrity constraints enforce conditions on relations between data, while security constraints enforce separation between data. If an integrity constraint is defined over data at different security levels, a direct conflict results. However, the solution is not to sacrifice the integrity constraint altogether. ...
متن کاملStarship Mission Destination Enterprise L Spying M 1 Rigel M 2 Enterprise L Spying M 1 ? Enterprise L ? Rigel M 2 5 Polyinstantiation Integrity Figure 6: Element-level Classiication 4.3 Tradeoo 4.2 Element-level Classiication
We characterized the information in a multilevel state of the world that is captured by a multilevel relational database. Based on the characterization, we formalized the security semantics of tuple-level and element-level data classiication schemes. Entity and referential integrity constraints for the multilevel relational model are derived from the security semantics. We also showed that the ...
متن کاملStoring OWL Ontologies in SQL Relational Databases
Relational databases are often used as a basis for persistent storage of ontologies to facilitate rapid operations such as search and retrieval, and to utilize the benefits of relational databases management systems such as transaction management, security and integrity control. On the other hand, there appear more and more OWL files that contain ontologies. Therefore, this paper proposes to ex...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- Journal of Computer Security
دوره 1 شماره
صفحات -
تاریخ انتشار 1992