The invention discloses a
database safety
access control method based on independent
authorization, and belongs to the field of
database safety. The designing thought that the method is in
loose coupling with a
database system is adopted,
access control on the basis of users instead of database accounts is realized by binding
database access behaviors with a USBKey, and control and audit can be conducted on behaviors of terminal users by correlating the
database access behaviors and the terminal users. Advanced
access control is introduced for conducting analyzing and monitoring on
database access statements, therefore, database
attack behaviors are shielded, insider operation behaviors are controlled and audited, and
information loss caused by the database attacking behaviors can be reduced. By
repackaging database access requests, monitoring and sniffing attacks are avoided. According to the technology, by adding the means of identity
authentication, access control and safety transmission which are independent from a database
management system, safety enhancing of a heterogeneous database
management system under multiple platforms is realized on the premise that the usage mode of an existing application
system is not changed.