CA2182592C

A method and apparatus for controlling access to a database

Abstract

The invention provides a method and apparatus controlling access to data (Row 1 to Row 5) in a database (32) and comprisesconfiguring at least part of the database (32) such that at least some of the data (Row 1 to Row 5) of the configured database (33) isassociated with a security tag (ROW_TAG), configuring a storage structure (35) of user identifiers (USER_NAME) and associated usertags (USER_TAG), configuring a storage structure (34) of user tags (USER_TAG) and associated security tags (ROW_TAG) and mappinga user identifier (USER_NAME) to at least a subset of the data (Row 1 to Row 5) by determining from the storage structure (34) of usertag (USER_TAG) and associated security tags (ROW_TAG) a security tag (ROW_TAG) or tags appropriate for the user tag (USER_TAG)of the user identifier (USER_NAME) and allowing access to the data (Row 1 to Row 5) from the configured database (33) associatedwith the security tag or tags (ROW_TAG). By providing a storage structure (34) of user tags (USER_TAG) and associated security tags(ROW_TAG) it is possible to change the security policy by modification of the data in the storage structure (34) alone without any needto modify the data (Row 1 to Row 5) in the configured database (33).

CA2182592C, drawing sheet 1
Sheet 1 of 6

Term

Term ended

Expired 14 February 2015, 11.6 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

4 claims: 2 independent, 2 dependent

  1. 1
    CA 02182592 1999-04-21 CLAIMS 1. A method of controlling access by a user to a database which comprises a set of data divided into sub-sets of data, said method comprising the steps of:assigning a single security tag to each sub-set of data in at least some of said sub-sets of data, assigning a user tag to an identifier for each user in a user table, assigning at least one security tag to each user tag in a security table, utilising the user table to obtain the user tag for the user, utilising the security table to obtain at least one security tag corresponding to the user tag, and permitting the user to access any sub-set of data having said at least one security tag.
  2. 3
    An apparatus for controlling access by a user to a database divided into sub-sets of data, said apparatus comprising means for assigning a single security tag to each sub-set of data in at least some of said sub-sets of data, means for assigning a user tag to an identifier for each user in a user table, means for assigning at least one security tag to each user tag in a security table, means for utilising the user table to obtain the user tag for a user, means for utilising the security table to obtain at least one security tag corresponding to a user tag, and means for permitting a user to access any sub-set of data having said at least one security tag.