IP Library Granted Patent US 12670279
Granted Patent B2
US 12670279 · App. 18/239,958 · Granted Jun 30, 2026

Database management system using policy labels, role patterns, roles, and access control relating thereto in metadata of a target table

Inventors: Chihiro Morita (Osaka, JP); Naoki Umeda (Akashi, JP); Takuma Maeda (Kobe, JP); Yuho Shiinoki (Akashi, JP); Nobuyuki Washio (Akashi, JP); Kosuke Suzuki (Ota, JP)
Assignee: Fujitsu Limited
G06F21/6218H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12670279
App. No.
18/239,958
Granted
Jun 30, 2026
Kind
B2
Abstract

A recording medium storing a program and method causing a computer to: store a first policy label according to a data type to be stored in a target table in metadata of the target table; refer to policy management information that defines content of access control that is performed on each role pattern and specifying the content of the access control that is performed on the each role pattern that corresponds to the first policy label stored in the metadata, for each of policy label that includes the first policy label; and refer to role management information that represents a correspondence between the each role pattern and roles in the target table and create access control information that represents content of access control that is performed on a role based on the specified content of the access control that is performed on the each role pattern.

Claims (50)

1 . A non-transitory computer-readable recording medium storing a database management program for causing a computer to execute processing comprising:

(1) in response to creating a target table that is an access control target in a database, storing, in metadata of the target table, a first policy label associated with a first data type to be stored in the target table; and

(2) in response to the storing of the first policy label in the metadata of the target table:

(2-1) referring to a policy management database configured to store, for each policy label of a plurality of policy labels each associated with a respective data type, policy management information that indicates, for each role pattern of a plurality of role patterns, content of access control that is to be performed on the each role pattern;

(2-2) specifying, from the policy management database, the policy management information corresponding to the first policy label stored in the metadata of the target table;

(2-3) referring to a role management database configured to store, for each table of a plurality of tables including the target table in the database, role management information that indicates a correspondence between the each role pattern and one or more specific roles in the each table;

(2-4) specifying, from the role management database, the role management information corresponding to the target table; and

(2-5) creating, based on the specified policy management information and the specified role management information, access control information that indicates, for each specific role identified in the specified role management information, as content of access control that is to be performed on the each specific role, the content of access control defined for the role pattern corresponding to the each specific role, as indicated in the specified policy management information,

wherein the role patterns include at least one of a data administrator, a web application user, and a batch application user.

2 . The non-transitory computer-readable recording medium according to claim 1 , for causing the computer to execute processing further comprising:

outputting the created access control information.

3 . The non-transitory computer-readable recording medium according to claim 1 , for causing the computer to execute processing further comprising:

referring to an access control status with respect to the target table in the database and creating access control execution information that represents content of access control performed on a role for the each role in the target table; and

detecting a difference portion of the access control execution information with respect to the access control information based on a comparison result of comparing the access control information with the access control execution information.

4 . The non-transitory computer-readable recording medium according to claim 3 , for causing the computer to execute processing further comprising:

outputting information from which the detected difference portion is capable of being specified.

5 . The non-transitory computer-readable recording medium according to claim 3 , for causing the computer to execute processing further comprising:

when receiving a login request from a first role with respect to the database, determining whether or not the first role is a role that corresponds to the difference portion;

in a case where the first role is the role that corresponds to the difference portion, rejecting login of the first role; and

in a case where the first role is not the role that corresponds to the difference portion, permitting the login of the first role.

6 . The non-transitory computer-readable recording medium according to claim 5 , wherein

when the login request is received, an access control status with respect to the target table in the database is referred, and the access control execution information is created,

the difference portion is detected based on a comparison result of comparing the access control information with the access control execution information, and

determining whether or not the first role is a role that corresponds to the detected difference portion.

7 . The non-transitory computer-readable recording medium according to claim 3 , for causing the computer to execute processing further comprising:

referring to the access control information and correcting content of access control to be performed on a role that corresponds to the difference portion in the target table.

8 . The non-transitory computer-readable recording medium according to claim 1 , for causing the computer to execute processing further comprising:

referring to the policy management information and specifying the each role pattern that corresponds to the first policy label;

receiving designation of one or more roles that correspond to the each specified role pattern, in the target table; and

creating the role management information in which the each role pattern in the target table is associated with the one or more designated roles.

9 . A database management method executed on a computer including a memory, the method comprising:

(1) in response to creating a target table that is an access control target in a database, storing, in metadata of the target table, a first policy label associated with a first data type to be stored in the target table; and

(2) in response to the storing of the first policy label in the metadata of the target table:

(2-1) referring to a policy management database configured to store, for each policy label of a plurality of policy labels each associated with a respective data type, policy management information that indicates, for each role pattern of a plurality of role patterns, content of access control that is to be performed on the each role pattern;

(2-2) specifying, from the policy management database, the policy management information corresponding to the first policy label stored in the metadata of the target table;

(2-3) referring to a role management database configured to store, for each table of a plurality of tables including the target table in the database, role management information that indicates a correspondence between the each role pattern and one or more specific roles in the each table;

(2-4) specifying, from the role management database, the role management information corresponding to the target table; and

(2-5) creating, based on the specified policy management information and the specified role management information, access control information that indicates, for each specific role identified in the specified role management information, as content of access control that is to be performed on the each specific role, the content of access control defined for the role pattern corresponding to the each specific role, as indicated in the specified policy management information,

wherein the role patterns include at least one of a data administrator, a web application user, and a batch application user.

10 . An information processing device comprising:

a memory; and

a processor coupled to the memory and configured to:

(1) in response to creating a target table that is an access control target in a database, store, in metadata of the target table, a first policy label associated with a first data type to be stored in the target table; and

(2) in response to the storing of the first policy label in the metadata of the target table:

(2-1) refer to a policy management database configured to store, for each policy label of a plurality of policy labels each associated with a respective data type, policy management information that indicates, for each role pattern of a plurality of role patterns, content of access control that is to be performed on the each role pattern;

(2-2) specify, from the policy management database, the policy management information corresponding to the first policy label stored in the metadata of the target table;

(2-3) refer to a role management database configured to store, for each table of a plurality of tables including the target table in the database, role management information that indicates a correspondence between the each role pattern and one or more specific roles in the each target table; and

(2-4) specify, from the role management database, the role management information corresponding to the target table; and

(2-5) creating, based on the specified policy management information and the specified role management information, access control information that indicates, for each specific role identified in the specified role management information, as content of access control that is to be performed on the each specific role, the content of access control defined for the role pattern corresponding to the each specific role, as indicated in the specified policy management information,

wherein the role patterns include at least one of a data administrator, a web application user, and a batch application user.