节点文献
数据库访问控制理论方法研究与实现
Research and Implement on the Technology and Theories of Access Controls
【作者】 赵宝献;
【导师】 秦小麟;
【作者基本信息】 南京航空航天大学 , 计算机应用技术, 2005, 硕士
【摘要】 信息技术的迅速发展使数据库面临的安全更加复杂,访问控制(Access Control)是数据库安全领域的一个重要部分。本文对访问控制理论做了全面和深入的讨论,并且给出了我们研究的 NHSDB 安全数据库的 MRBAC 访问控制体系的具体实现。 本文首先回顾了传统的数据库访问控制各自存在的缺点,并总结了传统访问控制的不足之处,由此引出了现代访问控制方法---使用控制(Usage Control,UCON),在此基础上总结了数据库访问控制技术的发展现状,分析了在此方面进行研究的难点和需要解决的关键问题。然后针对现代访问控制中时间限制和权力消耗的问题,本文提出了一种新的访问控制模型---基于次数限制的访问控制模型。在该模型中,通过次数限定来规定特权可以使用的最大次数。当权利的次数使用完或者授权有效期结束,授权将自动取消。这样可有效地防止系统资源的滥用,同时也减轻了管理员的负担。在前面讨论的基础上,我们进一步对 UCON 控制中的易变属性问题作了试探性讨论。同时,我们给出了我们开发的 NHSDB 安全数据库的 MRBAC 访问控制体系的具体实现,最后给出本文的结论和我们进一步研究的工作。
【Abstract】 With the rapid development of information and technology, database faces more serious security situation. Research in the access controls has been an important part of the area of the database. In this paper, we not only discuss the theories of access controls in details, but also give the detailed discussions for implementing MRBAC, the access control mechanism for NHSDB, a secure DBMS prototype. Firstly, in this paper, we review traditional access controls and analysis shortcomings of them. And then, the paper summaries disadvantages of traditional access controls and introduces modern access control---usage control. In order to solve the problems that usage of a digital object can be not only time-constrained, but also temporal and privilege-consuming, in recent information systems.,we present a new access control model—A Times-based Limited Access control Model. This model defines the maximum times that privileges can be exercised. When the times of privileges is consumed to zero or the period of authorizations is expired, the privilege exercised on objects will be automatically revoked by the system. This model protects system resources from being abused to a certain extent and alleviates the burden of system administrators. Based on what we discuss, we give an initial discussion for mutability attributes in the UCON. At the same time, we introduce the implement for MRBAC, the access control mechanism for NHSDB, a secure DBMS prototype. Finally, we draw a conlusion for this paper and future direction in this field is discussed.
【Key words】 Access Control; Information Security; Usage Control(UCON); Authorization; Security Database; DBMS;
- 【网络出版投稿人】 南京航空航天大学 【网络出版年期】2005年 05期
- 【分类号】TP311.13;TP309
- 【被引频次】14
- 【下载频次】415