ACM SIGMOD Anthology ACM SIGMOD dblp.uni-trier.de

An Authorization Mechanism for a Relational Data Base System (Abstract).

Patricia P. Griffiths, Bradford W. Wade: An Authorization Mechanism for a Relational Data Base System (Abstract). SIGMOD Conference 1976: 51
@inproceedings{DBLP:conf/sigmod/GriffithsW76,
  author    = {Patricia P. Griffiths and
               Bradford W. Wade},
  editor    = {James B. Rothnie Jr.},
  title     = {An Authorization Mechanism for a Relational Data Base System
               (Abstract)},
  booktitle = {Proceedings of the 1976 ACM SIGMOD International Conference on
               Management of Data, Washington, D.C., June 2-4, 1976},
  publisher = {ACM},
  year      = {1976},
  pages     = {51},
  ee        = {http://doi.acm.org/10.1145/509383.509393, db/conf/sigmod/GriffithsW76.html},
  crossref  = {DBLP:conf/sigmod/76},
  bibsource = {DBLP, http://dblp.uni-trier.de}
}
BibTeX

Abstract

A multi-user data base system must permit users to selectively share data, while retaining the ability to restrict data access. There must be a mechanism to provide protection and security, permitting information to be accessed only by properly authorized users. Further, when tables or restricted views of tables are created and destroyed dynamically, the granting, authentication, and revocation of authorization to use them must also be dynamic. We discuss each of these issues and their solutions in the context of the relational data base management system, System R.

When a data base user creates a table, he is fully and solely authorized to perform actions upon it such as read, insert, update, and delete. If he wishes, he may explicitly grant to any other user any or all of his privileges on the table. In addition, he may specify that that user is authorized to further grant these privileges to other users. The result is a directed graph of granted privileges originating from the table creator.

At some later time, a user A may revoke some or all of the privileges which he previously granted to another user B. This action usually revokes the entire subgraph of the grants originating from A's grant to B. It may be, however, that B will still possess the revoked privileges by means of a grant from another user C, and therefore some or all of B's grants should not be revoked. We discuss this problem in detail and present an algorithm for detecting exactly which of B's grants should be revoked.

Because revocation may be performed dynamically, a user's authorization for a table must be checked dynamically. We present a scheme which attempts to minimize the cost of such revalidation.

Copyright © 1976 by the ACM, Inc., used by permission. Permission to make digital or hard copies is granted provided that copies are not made or distributed for profit or direct commercial advantage, and that copies show this notice on the first page or initial screen of a display along with the full citation.


ACM SIGMOD Anthology

Online Version (ACM WWW Account required): Full Text in PDF Format

CDROM Version: Load the CDROM "Volume 1 Issue 2, SIGMOD '75-'92" and ...

DVD Version: Load ACM SIGMOD Anthology DVD 1" and ... BibTeX

Printed Edition

James B. Rothnie Jr. (Ed.): Proceedings of the 1976 ACM SIGMOD International Conference on Management of Data, Washington, D.C., June 2-4, 1976. ACM 1976 BibTeX
Contents

Journal Version

Patricia P. Griffiths, Bradford W. Wade: An Authorization Mechanism for a Relational Database System. ACM Trans. Database Syst. 1(3): 242-255(1976) BibTeX

Referenced by

  1. Elisa Bertino: Review - An Authorization Mechanism for a Relational Data Base System. ACM SIGMOD Digital Review 1: (1999)
  2. Morton M. Astrahan, Mike W. Blasgen, Donald D. Chamberlin, Kapali P. Eswaran, Jim Gray, Patricia P. Griffiths, W. Frank King III, Raymond A. Lorie, Paul R. McJones, James W. Mehl, Gianfranco R. Putzolu, Irving L. Traiger, Bradford W. Wade, Vera Watson: System R: Relational Approach to Database Management. ACM Trans. Database Syst. 1(2): 97-137(1976)
BibTeX
ACM SIGMOD Anthology - DBLP: [Home | Search: Author, Title | Conferences | Journals]
ACM SIGMOD Anthology: Copyright © by ACM (info@acm.org), Corrections: anthology@acm.org
DBLP: Copyright © by Michael Ley (ley@uni-trier.de), last change: Sat May 16 23:39:14 2009