Access control and audit model for the multidimensional modeling of data warehouses

被引:38
作者
Fernandez-Medina, Eduardo
Trujillo, Juan
Villarroel, Rodolfo
Piattini, Mario
机构
[1] Univ Castilla La Mancha, Escuela Super Informat, E-13071 Ciudad Real, Spain
[2] Univ Castilla La Mancha, Dept Informat, E-13071 Ciudad Real, Spain
[3] Univ Alicante, Dept Lenguajes & Sistemas Informat, E-03080 Alicante, Spain
关键词
data warehouses; secure multidimensional modeling; access control; audit; UML;
D O I
10.1016/j.dss.2005.10.008
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Due to the sensitive data contained in Data Warehouses (DW), it is essential to specify security measures from the early stages of the DW design and enforce them. Traditional access control models for transactional (relational) databases, based on tables, columns and rows, are not appropriate for DWs. Instead, security and audit rules defined for DWs must be specified based on the multidimensional (MD) modeling used to design data warehouses. Current approaches for the conceptual modeling of DWs do not allow us to specify security and confidentiality constraints in the conceptual modeling phase. In this paper, we propose an Access Control and Audit (ACA) model for DWs by specifying security rules in the conceptual MD modeling. Thus, we define authorization rules for users and objects and we assign sensitive information rules and authorization rules to the main elements of a MD model (e.g., facts or dimensions). Moreover, we also specify certain audit rules allowing us to analyze user behaviors. To be able to include and use our ACA model in the conceptual MD modeling, we extend the Unified Modeling Language (UML) with our ACA model, thereby allowing us to design secure MD models. Finally, to show the benefit of our approach, we apply our approach to a health care case study. (c) 2005 Elsevier B.V. All rights reserved.
引用
收藏
页码:1270 / 1289
页数:20
相关论文
共 52 条
[1]  
ABELLO A, 2002, INT DAT ENG APPL S I
[2]  
ABELLO A, 2001, LNCS, V2113
[3]  
ATLURI V, 1996, 5 EUR S RES COMP SEC
[4]  
BERTINO E, 1999, ACM T INFORM SYSTEMS, V17
[5]  
BLASCHKA M, 1998, 9 INT C DAT EXP SYST
[6]  
BOLLOJU N, 2002, DECISION SUPPORT SYS, V32
[7]  
BONATTI P, 2001, IFIP TC11 INT C INF
[8]  
COTA S, 2004, DB2 MAGAZINE, V9
[9]  
DAMIANI E, 2002, ACM T INFORM SYSTEMS, V5
[10]  
DAMIANI E, 2002, RES DIRECTIONS DATA