Systems and methods for attribute based access control on a data lake
Systems and methods for attribute based access control on a data lake. The systems and methods include receiving a data file and metadata associated with the data file, storing the data file in a database and storing the metadata in a data catalog. The metadata is assigned a domain access configuration and an attribute access configuration. The systems and methods further include receiving a query for the data file from a user, where the user is assigned a persona, where persona comprises a permission level. Syntax of the query is evaluated in addition to access to the query through steps including evaluating the permission level of the assigned persona against the domain access configuration and evaluating the permission level of the assigned persona against the attribute access configuration. In response to determining that the query fails to satisfy one or more of the evaluations, the query is then rejected.
1 . A method comprising:
receiving a data file and metadata associated with the data file;
storing the data file in a database, and storing the metadata associated with the data in a data catalog;
assigning the metadata a domain access configuration and an attribute access configuration;
receiving a query for the data file from a user, wherein the user is assigned a persona from a plurality of personas, each comprising a permission level;
validating a syntax of the query;
invoking a security administrator to evaluate access to the query through steps comprising:
evaluating the permission level of the assigned persona against the domain access configuration;
evaluating the permission level of the assigned persona against the attribute access configuration; and
in response to determining, by the security administrator, that the query fails to satisfy one or more of the evaluations, rejecting the query; and
automatically testing the security administrator through steps comprising:
entering a test state, wherein each query received by the user is rejected;
for each persona of a specified set of the plurality of personas:
assigning a proxy user to the persona with the corresponding permission level;
initiating a test query for a test data file;
invoking the security administrator to evaluate access to the test query; and
generating a test result indicating whether the proxy user was impermissibly granted access to the test data file based on the permission level; and
in response to one or more of the test results indicating the proxy user was impermissibly granted access to the test data file, outputting an alert.
2 . The method of claim 1 , wherein assigning the metadata the domain access configuration comprises:
selectively approving access to a domain interface based on domain ownership data;
receiving a domain metadata tag for a set of data file types; and
assigning the metadata the domain access configuration.
3 . The method of claim 1 , wherein the metadata is further assigned a zone access configuration, and the security administrator further evaluates access to the query through evaluating the permission level against the zone access configuration.
4 . The method of claim 1 , wherein the metadata, upon invocation of the security administrator, lacks a classification tag, further wherein in response, the metadata is assigned an unclassified tag, and rejecting the query.
5 . The method of claim 1 , wherein invoking the security administrator comprises transmitting the metadata to the security administrator via asynchronous integration.
6 . The method of claim 1 , wherein each persona is assigned the corresponding permission level based in part on an operating environment of the database.
7 . A system comprising
one or more processors configured to:
receive a data file and metadata associated with the data file;
store the data file in a database, and store the metadata associated with the data file in data catalog;
assign the metadata a domain access configuration and an attribute access configuration;
receive a query for the data file from a user, wherein the user is assigned a persona from a plurality of personas, each comprising a permission level;
validate a syntax of the query;
invoke a security administrator to evaluate access to the query through steps comprising:
evaluating the permission level of the assigned persona against the domain access configuration;
evaluating the permission level of the assigned persona against the attribute access configuration;
in response to determining, by the security administrator, that the query fails to satisfy one or more of the evaluations, reject the query; and
automatically testing the security administrator through steps comprising:
entering a test state, wherein each query received by the user is rejected;
for each persona of a specified set of the plurality of personas:
assigning a proxy user to the persona with the corresponding permission level;
initiating a test query for a test data file;
invoking the security administrator to evaluate access to the test query; and
generating a test result indicating whether the proxy user was impermissibly granted access to the test data file based on the permission level; and
in response to one or more of the test results indicating the proxy user was impermissibly granted access to the test data file, outputting an alert.
8 . The system of claim 7 , wherein the one or more processors are further configured to:
selectively approve access to a domain interface based on domain ownership data;
receive a domain metadata tag for a set of data file types; and
assign the metadata the domain access configuration.
9 . The system of claim 7 , wherein one or more processors are further configured to:
assign the metadata a zone access configuration; and
invoke the security administrator to further evaluate access to the query through evaluating the permission level against the zone access configuration.
10 . The system of claim 7 , wherein the metadata, upon invocation of the security administrator, lacks a classification tag, further wherein in response, the one or more processors are further configured to assign an unclassified tag, and reject the query.
11 . The system of claim 7 , wherein, in invoking the security administrator, the one or more processors are further configured to transmit the metadata to the security administrator via asynchronous integration.
12 . The system of claim 7 , wherein the one or more processors are further configured to assign each persona the corresponding permission level based in part on an operating environment of the database.
13 . A non-transitory computer readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to:
receive a data file and metadata associated with the data file;
store the data file in a database, and store the metadata associated with the data file in a data catalog;
assign the metadata a domain access configuration and an attribute access configuration;
receive a query for the data file from a user, wherein the user is assigned a persona from a plurality of personas, each comprising a permission level;
validate a syntax of the query;
invoke a security administrator to evaluate access to the query through steps comprising:
evaluating the permission level of the assigned persona against the domain access configuration;
evaluating the permission level of the assigned persona against the attribute access configuration;
in response to determining, by the security administrator, that the query fails to satisfy one or more of the evaluations, reject the query; and
automatically testing the security administrator through steps comprising:
entering a test state, wherein each query received by the user is rejected;
for each persona of a specified set of the plurality of personas:
assigning a proxy user to the persona with the corresponding permission level;
initiating a test query for a test data file;
invoking the security administrator to evaluate access to the test query; and
generating a test result indicating whether the proxy user was impermissibly granted access to the test data file based on the permission level; and
in response to one or more of the test results indicating the proxy user was impermissibly granted access to the test data file, outputting an alert.
14 . The non-transitory computer readable medium of claim 13 , the non-transitory computer readable medium storing further instructions that, when executed by one or more processors, cause the one or more processors to:
selectively approve access to a domain interface based on domain ownership data;
receive a domain metadata tag for a set of data file types; and
assign the metadata the domain access configuration.
15 . The non-transitory computer readable medium of claim 13 , the non-transitory computer readable medium storing further instructions that, when executed by one or more processors, cause the one or more processors to:
assign the metadata a zone access configuration; and
invoke the security administrator to further evaluate access to the query through evaluating the permission level against the zone access configuration.
16 . The non-transitory computer readable medium of claim 13 , wherein the metadata, upon invocation of the security administrator, lacks a classification tag, further wherein in response, the one or more processors are further caused to assign an unclassified tag, and reject the query.