Title :
Authorization and revocation in object-oriented databases
Author :
Majetic, Ivo ; Leiss, Ernst L.
Author_Institution :
Dept. of Comput. Sci., Houston Univ., TX, USA
Abstract :
Few studies of object-oriented databases deal with their security, a fundamental aspect of systems with complex data structures. Most authorization systems give users who own resources only some basic control over them; here, we provide users with more direct control over their resources by associating with each grant propagation numbers. Propagation numbers govern the grantability and exercisability of the privileges. Of particular interest in our study of authorization in an OO environment is the combination of inheritance and granting of privileges. Diverse policies are discussed and implemented in a test-bed system
Keywords :
authorisation; data structures; inheritance; object-oriented databases; security of data; authorization; complex data structures; inheritance; object-oriented databases; privileges; propagation numbers; revocation; security; testbed system; Authorization; Computer languages; Control systems; Data security; Data structures; Database systems; Object oriented databases; Object oriented programming; Relational databases; System testing;
Journal_Title :
Knowledge and Data Engineering, IEEE Transactions on