As organizations depend on, possibly distributed, information systems for operational, decisional and strategic activities, they are vulnerable to security breaches leading to data theft and unauthorized disclosures even as they gain productivity and efficiency advantages. Though several techniques, such as encryption and digital signatures, are available to protect data when transmitted across sites, a truly comprehensive approach for data protection must include mechanisms for enforcing access control policies based on data contents, subject qualifications and characteristics, and other relevant contextual information, such as time. It is well understood today that the semantics of data must be taken into account in order to specify effective access control policies. To address such requirements, over the years the database security research community has developed a number of access control techniques and mechanisms that are specific to database systems. In this monograph, we present a comprehensive state of the art about models, systems and approaches proposed for specifying and enforcing access control policies in database management systems. In addition to surveying the foundational work in the area of access control for database systems, we present extensive case studies covering advanced features of current database management systems, such as the support for fine-grained and context-based access control, the support for mandatory access control, and approaches for protecting the data from insider threats. The monograph also covers novel approaches, based on cryptographic techniques, to enforce access control and surveys access control models for objectdatabases and XML data. For the reader not familiar with basic notions concerning access control and cryptography, we include a tutorial presentation on these notions. Finally, the monograph concludes with a discussion on current challenges for database access control and security, and preliminary approaches addressing some of these challenges.
Article navigation
1 March 2011
Research Article|
March 01 2011
Access Control for Databases: Concepts and Systems
Elisa Bertino;
Elisa Bertino
CS Department, Purdue University
, West Lafayette, IN, 47907, USA
Search for other works by this author on:
Gabriel Ghinita;
Gabriel Ghinita
CS Department, Purdue University
, West Lafayette, IN, 47907, USA
Search for other works by this author on:
Ashish Kamra
Ashish Kamra
ECE Department, Purdue University
, West Lafayette, IN, 47907, USA
Search for other works by this author on:
Online ISSN: 1931-7891
Print ISSN: 1931-7883
© 2011 E. Bertino, G. Ghinita and A. Kamra
2011
E. Bertino, G. Ghinita and A. Kamra
Licensed re-use rights only
Foundations and Trends in Databases (2011) 3 (1-2): 1–148.
Citation
Bertino E, Ghinita G, Kamra A (2011), "Access Control for Databases: Concepts and Systems". Foundations and Trends in Databases, Vol. 3 No. 1-2 pp. 1–148, doi: https://doi.org/10.1561/1900000014
Download citation file:
Suggested Reading
Building your own ERMS
Library Hi Tech News (May,2015)
Green human resource management and corporate social responsibility: Evidence from Brazilian firms
Benchmarking: An International Journal (April,2020)
Object‐oriented database systems in manufacturing: selection and applications
Industrial Management & Data Systems (April,2001)
Capability based formulation and solution of multiple objective cell formation problems using simulated annealing
Integrated Manufacturing Systems (July,2001)
The effects of IT expenditures on banks’ business performance: using a balanced scorecard approach
Managerial Finance (June,2004)
Related Chapters
Financial Architecture and Monetary Policy Transmission Mechanism in Kenya
Risk Management Post Financial Crisis: A Period of Monetary Easing
Recommended for you
These recommendations are informed by your reading behaviors and indicated interests.
