Global authorizations in database federations can be derived from local authorizations exported by the databases composing the federation. Particularly, when several component databases participate in the federation and a high number of users and protection objects are involved, techniques are needed for defining and managing global access privileges. This paper describes an automated approach for the derivation of global authorizations according to the policy of decentralized minimum privilege, based on the analysis of authorizations exported by component databases. The approach rakes into account both the security requirements of the constituent databases, to preserve their local authorization autonomy, and cooperation requirements, to concurrently enable flexible data sharing between the constituent databases. A federation authorization model and abstraction criteria to derive global authorizations that are consistent with the exported local ones are presented. Different abstraction strategies can be applied for derivation, depending on the nature of the global objects to be protected and on the security requirements of the federated system.

Automated derivation of global authorizations for database federations / S. Castano, S. De Capitani di Vimercati, M. Fugini. - In: JOURNAL OF COMPUTER SECURITY. - ISSN 0926-227X. - 5:4(1997), pp. 271-301. [10.3233/JCS-1997-5402]

Automated derivation of global authorizations for database federations

S. Castano
Primo
;
S. De Capitani di Vimercati
Secondo
;
1997

Abstract

Global authorizations in database federations can be derived from local authorizations exported by the databases composing the federation. Particularly, when several component databases participate in the federation and a high number of users and protection objects are involved, techniques are needed for defining and managing global access privileges. This paper describes an automated approach for the derivation of global authorizations according to the policy of decentralized minimum privilege, based on the analysis of authorizations exported by component databases. The approach rakes into account both the security requirements of the constituent databases, to preserve their local authorization autonomy, and cooperation requirements, to concurrently enable flexible data sharing between the constituent databases. A federation authorization model and abstraction criteria to derive global authorizations that are consistent with the exported local ones are presented. Different abstraction strategies can be applied for derivation, depending on the nature of the global objects to be protected and on the security requirements of the federated system.
Settore INF/01 - Informatica
1997
Article (author)
File in questo prodotto:
Non ci sono file associati a questo prodotto.
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/2434/179404
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 6
  • ???jsp.display-item.citation.isi??? ND
social impact