Providing Dynamic Security Control in a Federated Database

Norbik Bashah Idris, William A. Gray, Robert F. Churchhouse · 1994

When data is being used in a federated database, the aim is to give a loose coupling of the data in the component databases so that a very dynamic and therefore flexible pattern of data sharing can be established. When se-curity integration is performed this flexibility is curtailed by the resultant security level es-tablished at integration time which by default is the least upper bound between candidate security levels. Such overclassification of data implies that. there willbe author&d users who are debarred at the federation level to access the data. To circumvent this problem there is a need for a dynamic mandate type control for definite periods of the federated system’s exk tence. An approach to establishing su:h tem-porary dynamic security control is described in this paper. It is an adaptation of Shamir’s method [Sha79] for sharing a secret., and it aims to let users who are debarred at the de-fault security level from access to particular data, gain access to this data under local con-trol if an appropriate combination of current, database administrator of the system are pre-pared to grant, the access dynamically. Permirrion to copy without fee all or part of thir material ir granted provided that the copies are not made or di8tributed for direct commercial advantage, the VLDB copyright notice and the title of the publication and it8 date appear, and notice i8 given that copying is by permisrion of the Very Large Data Bare Endowment. To copy otherwi8e, or to npubGh, require8 a fee and/or rpeeial pemirrion from the Endowment. /

Read the paper · More papers on PaperTik