Access control is the enforcement of the authorization policy, which defines subjects, resources, and access rights. Graph-structured data requires advanced, flexible, and fine-grained access control due to its complex structure as sequences of alternating vertices and edges. Several research works focus on protecting property graph-structured data, enforcing fine-grained access control, and proving the feasibility and applicability of their concept. However, they differ conceptually and technically. We select works from our systematic literature review on authorization and access control for different database models in addition to recent ones. Based on defined criteria, we exclude research works with different objectives, such as no protection of graph-structured data, graph models other than the property graph, coarse-grained access control approaches, or no application in a graph datastore (i.e., no proof-of-concept implementation). The latest version of the remaining works are discussed in detail in terms of their access control approach as well as authorization policy definition and enforcement. Finally, we analyze the strengths and limitations of the selected works and provide a comparison with respect to different aspects, including the base access control model, open/closed policy, negative permission support, and datastore-independent enforcement.
翻译:访问控制是授权策略的实施,该策略定义了主体、资源和访问权限。图结构数据由于具有顶点和边交替序列的复杂结构,需要先进、灵活且细粒度的访问控制。若干研究工作聚焦于保护属性图结构数据、实施细粒度访问控制,并证明了其概念的可行性与适用性。然而,这些研究在概念和技术层面存在差异。我们从针对不同数据库模型的授权与访问控制系统文献综述中选取了相关研究,并补充了近期成果。基于既定标准,我们排除了目标不同的研究工作,例如不涉及图结构数据保护、使用非属性图模型、采用粗粒度访问控制方法,或未在图数据库(即缺乏概念验证实现)中应用的研究。我们对剩余研究的最新版本进行了详细讨论,涵盖其访问控制方法以及授权策略的定义与实施。最后,我们分析了所选研究的优势与局限,并从多个维度进行了比较,包括基础访问控制模型、开放/封闭策略、负权限支持以及数据存储无关的实施机制。