|
Prikladnaya Diskretnaya Matematika, 2014, Number 2(24), Pages 48–78
(Mi pdm460)
|
|
|
|
This article is cited in 2 scientific papers (total in 2 papers)
Mathematical Foundations of Computer Security
Analysis of the conditions for granting and obtaining access rights in the MS SQL Server access control model
V. Y. Slolyaninov Moscow, Russia
Abstract:
In this paper, the MS SQL Server access control model, based on the DBMS DP-model, is introduced. For taking into account the access control features of Microsoft SQL Server, the model includes roles, permissions to user accounts and roles, ownership chaining, user impersonation and activating procedures and triggers on behalf of the specified user accounts. The statement of the equivalence of the possibilities to execute arbitrary SQL-code on behalf of a specified account and to obtain the right of its impersonation is proved. Some necessary and sufficient conditions for obtaining and granting access rights by entities in the absence of cooperation between sessions are proved.
Keywords:
computer security, MS SQL Server access control model, database management system.
Citation:
V. Y. Slolyaninov, “Analysis of the conditions for granting and obtaining access rights in the MS SQL Server access control model”, Prikl. Diskr. Mat., 2014, no. 2(24), 48–78
Linking options:
https://www.mathnet.ru/eng/pdm460 https://www.mathnet.ru/eng/pdm/y2014/i2/p48
|
Statistics & downloads: |
Abstract page: | 272 | Full-text PDF : | 76 | References: | 48 |
|