Title :
Fine-granularity access control in 3-tier laboratory information systems
Author :
Li, Xueli ; Naeem, Nomair A. ; Kemme, Bettina
Author_Institution :
Biotechnol. Res. Inst., National Res. Council, Ottawa, Ont., Canada
Abstract :
Laboratory information systems (LIMS) are used in life science research to manage complex experiments. Since LIMS systems are often shared by different research groups, powerful access control is needed to allow different access rights to different records of the same table. Traditional access control models that define a permission as the right of a user/role to perform a specific operation on a specific object cannot handle the enormous amount of objects and user/roles. In this paper, we propose an enhancement to role-based access control by introducing conditions that can be added to the traditional concept of permissions in order to keep the number of permissions small. Furthermore, we present an implementation of our access control model at the application programming level. Although access control is performed for every single database access, our solution completely separates access control from the application logic by using aspect-oriented programming. With this, access control can be integrated into a legacy 3-tier information system without changing the application programs.
Keywords :
authorisation; database management systems; laboratory techniques; 3-tier laboratory information systems; application programming level; aspect-oriented programming; database access; fine-granularity access control; legacy 3-tier information system; role-based access control; Access control; Computer science; Councils; Database systems; Information systems; Laboratories; Logic programming; Management information systems; Permission; Power system modeling;
Conference_Titel :
Database Engineering and Application Symposium, 2005. IDEAS 2005. 9th International
Print_ISBN :
0-7695-2404-4
DOI :
10.1109/IDEAS.2005.30