Title :
Authorization model for summary schemas model
Author :
Ngamsuriyaroj, Sudsanguan ; Hurson, Ali R. ; Keefe, Thomas F.
Author_Institution :
Dept. of Comput. Sci. & Eng., Pennsylvania State Univ., University Park, PA, USA
Abstract :
Security issues in multidatabases are complicated due to autonomy and heterogeneity of local databases. Deriving global authorizations by integrating underlying local authorizations is difficult since subjects and objects at each local database may not be compatible. In addition, local authorizations may conflict and could not be combined to form common global authorizations. This paper proposes an authorization model for a multidatabase system. The summary schemas model (SSM) is used as the underlying paradigm. The SSM resolves name differences in multidatabases using word relationships defined in a standard dictionary. Hypernyms and hyponyms of access terms exported from local databases are the main components of the SSM as they form a hierarchical metadata structure. SSM global authorizations tagged to hypernyms are derived from local authorizations using global roles and a role hierarchy defined in multidatabases. The model considers roles as common global subjects onto which local subjects can be mapped. Since the mapping can be done independently and autonomously among local databases, authorization autonomy is preserved. The paper also evaluates the performance of the proposed model. The simulation results show that the proposed model offers better performance than the original SSM since user queries with insufficient authority are rejected earlier. This results in less communication and less query response time.
Keywords :
authorisation; distributed databases; meta data; query processing; access terms; authorization model; common global subjects; global roles; hierarchical metadata structure; hypernyms; hyponyms; local databases; multidatabases; performance evaluation; query response time; role hierarchy; security; simulation; standard dictionary; summary schemas model; word relationships; Authorization; Computer science; Computer security; Data engineering; Data models; Data security; Database languages; Delay; Dictionaries; Distributed databases;
Conference_Titel :
Database Engineering and Applications Symposium, 2002. Proceedings. International
Print_ISBN :
0-7695-1638-6
DOI :
10.1109/IDEAS.2002.1029671