摘要
信息技术的迅速发展使数据库面临的安全问题更加复杂和多样,数据库作为信息系统重要数据的存储和处理核心,往往成为最吸引攻击者的目标。访问控制技术是数据库安全领域的一个重要研究方向,传统的访问控制技术已越来越不能满足现代数据库的安全需求。在传统的自主访问控制机制研究的基础上,提出了一种基于双授权链集合的访问控制模型(DACS)。该模型具有常规授权管理和阻断授权管理功能,支持8种授权和收权操作,同时具备阻断授权机制和独立收权机制。
With the rapid development of information and technology,database faces more serious security situation. As the center of storage and process for the important data,databases often become the targets of attacks. Research of the access control has been an important part in the field of database security, but the traditional access control technologies could not satisfy the requirements of modern database security. On the basis of traditional DAC mechanism research, we proposed a double-authorization chain sets based access control model(DACS), which supports 8 kinds of authorization management functions including normal authorization and denial authorization, and has denial authorization mechanism and non-cascade revoking mechanism.
出处
《计算机科学》
CSCD
北大核心
2010年第7期160-164,228,共6页
Computer Science
基金
国家自然科学基金资助项目(60673127)
863国家高技术研究发展计划基金资助项目(2007AA01Z404)
江苏省科技支撑计划(BE2008135)资助
关键词
安全数据库
访问控制
授权链集合
Secure database,Access control,Authorization chain sets