databases and authorization
Posted in 1995
I am looking for some computer aided help to manage and administrate authorization of databases in a client/server architecture in a fine granularity. The end user should be able to access the database both through standard applications (Excel, DesktopDBA etc) and own custom made applications. The application developer should be able to disable functionality that use database operations the user not is granted to do. Background: - It is complex to administrate authorization for database objects (tables, views and stored procedures) for all different users. - There is no support for authorization (filtering) on a row level (tuple level) in a standard DBMS. (Except by making views that does the job) There should be a structured way for the application developer to handle this so the filtering is made based on the user's current authorities. - It is seldom the case that a user of a custom made application has the authority to use all the functionality in the application. There should be a structured way for the developer to disable the functions that include operations to the database that the user has no authority to do. - The authorization of accessing data should not just be dependent of which user that wants to access it, but also from which application s/he wants to access it. Some database object that you are granted to access in a structured way from a custom application should not be able to be accessed in a unstructured way from a standard application. - The authorization should be time dependent. Both the period the authorization is valid and under which period under a day the user is granted to access the database. I am interested in commercial software that can help me out with anything of the above and/or tips of books or research in the area. If there is anything in my description that you do not understand due to the short description and my English please email me. /Rickard d91-ril@nada.kth.se