Searching for just a few words should be enough to get started. If you need to make more complex queries, use the tips below to guide you.
Article type: Research Article
Authors: Bertino, Elisa | Origgi, Fabio | Samarati, Pierangela
Affiliations: Dipartimento di Scienze dell'Informazione, Università di Milano, Milano, Italy
Note: [*] A preliminary version of this paper appeared in Proceedings of the 8th Working Conference on Database Security, Bad Salzdetfurth, Germany, August 1994 [5].
Abstract: Object-oriented database systems represent today one of the most promising technology to a number of applications in business and industry. A serious problem with these systems is that they do not provide adequate access control mechanisms for controlling access to information. One of the most significant proposal for the protection of OODBMSs is represented by the Orion authorization model. In the Orion authorization model several concepts have been introduced such as those of implicit/explicit and strong/weak authorizations. However, the Orion authorization model suffers from some drawbacks and addresses only partially some protection problems. In this paper we present an authorization model for the protection of object-oriented database systems based on the types of authorizations introduced in the Orion authorization model. Although based on the same concepts, our model differs from Orion in many respects. The main differences concern the semantics of negative authorizations and of user groups. These differences result in different implication rules for the derivation of authorizations. In the paper we also discuss the problems of authorization administration, creation of new objects, and access control.
DOI: 10.3233/JCS-1994/1995-32-305
Journal: Journal of Computer Security, vol. 3, no. 2-3, pp. 169-206, 1995
IOS Press, Inc.
6751 Tepper Drive
Clifton, VA 20124
USA
Tel: +1 703 830 6300
Fax: +1 703 830 2300
sales@iospress.com
For editorial issues, like the status of your submitted paper or proposals, write to editorial@iospress.nl
IOS Press
Nieuwe Hemweg 6B
1013 BG Amsterdam
The Netherlands
Tel: +31 20 688 3355
Fax: +31 20 687 0091
info@iospress.nl
For editorial issues, permissions, book requests, submissions and proceedings, contact the Amsterdam office info@iospress.nl
Inspirees International (China Office)
Ciyunsi Beili 207(CapitaLand), Bld 1, 7-901
100025, Beijing
China
Free service line: 400 661 8717
Fax: +86 10 8446 7947
china@iospress.cn
For editorial issues, like the status of your submitted paper or proposals, write to editorial@iospress.nl
如果您在出版方面需要帮助或有任何建, 件至: editorial@iospress.nl