Web: http://arxiv.org/abs/2209.05561

Sept. 14, 2022, 1:20 a.m. | Hoang Nguyen Phuoc-Bao, Manuel Clavel

cs.CR updates on arXiv.org arxiv.org

Recently, we have proposed a model-driven approach for enforcing fine-grained
access control (FGAC) policies when executing SQL queries. More concretely, we
have defined a function SecQuery() that, given an FGAC policy S and a SQL
select-statement q, generates a SQL stored-procedure SecQuery(S, q), such that:
if a user u with role r is authorised, according to S, to execute q based on
the current state of the database, then calling SecQuery(S, q)(u, r) returns
the same result as when u …

access access control control database policy

