×

Two phase intermediate query security using access control

  • US 20050050046A1
  • Filed: 08/29/2003
  • Published: 03/03/2005
  • Est. Priority Date: 08/29/2003
  • Status: Active Grant
First Claim
Patent Images

1. In a networked client-server computer system having a plurality of users of the client-server system and including software performing database queries via a DBMS for users of the system, a method of two-phase query security, the method comprising:

  • receiving by the client system a query string from one of the plurality of users, the query string including references to database objects;

    transforming the received query string by the client system to an intermediate query string;

    performing a first phase query security by the client system including;

    identifying the referenced database objects; and

    inserting a security marker into the intermediate query string for each respective identified database object, thereby forming respective pairs of query parts and marker parts;

    transferring the intermediate query string, including the query parts and the marker parts, to the server system;

    performing access control checks by the server system on the inserted security markers in the intermediate query string; and

    replacing the inserted security markers with corresponding enforcing means to enforce access control.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×