• DocumentCode
    258145
  • Title

    Role-Based Access control mechanisms

  • Author

    Mortagua Pereira, Oscar ; Domingues Regateiro, Diogo ; Aguiar, Rui L.

  • Author_Institution
    DETI, Univ. of Aveiro, Aveiro, Portugal
  • fYear
    2014
  • fDate
    23-26 June 2014
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    Most of the security threats in relational database applications have their source in client-side systems when they issue requests formalized by Create, Read, Update and Delete (CRUD) expressions. If tools such as ODBC and JDBC are used to develop business logics, then there is another source of threats. In some situations the content of data sets retrieved by Select expressions can be modified and then committed into the host databases. These tools are agnostic regarding not only database schemas but also regarding the established access control policies. This situation can hardly be mastered by programmers of business logics in database applications with many and complex access control policies. To overcome this gap, we extend the basic Role-Based Access policy to support and supervise the two sources of security threats. This extension is then used to design the correspondent RBAC model. Finally, we present a software architectural model from which static RBAC mechanisms are automatically built, this way relieving programmers from mastering any schema. We demonstrate empirical evidence of the effectiveness of our proposal from a use case based on Java and JDBC.
  • Keywords
    Java; authorisation; relational databases; CRUD expressions; JDBC; Java; RBAC mechanisms; business logics; create read update and delete expressions; relational database applications; role-based access control mechanisms; security threats; select expressions; Access control; Business; Data structures; Databases; Java; Runtime; RBAC; access control; databases; distributed systems; information security; middleware; software architecture;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computers and Communication (ISCC), 2014 IEEE Symposium on
  • Conference_Location
    Funchal
  • Type

    conf

  • DOI
    10.1109/ISCC.2014.6912546
  • Filename
    6912546