OBSERVATION-BASED FINE GRAINED ACCESS CONTROL FOR RELATIONAL DATABASES

被引:0
|
作者
Halder, Raju [1 ]
Cortesi, Agostino [1 ]
机构
[1] Univ Ca Foscari Venezia, Dipartimento Informat, Venice, Italy
关键词
Access control; Relational databases; Abstract interpretation;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Fine Grained Access Control (FGAC) provides users the access to the non-confidential database information while preventing unauthorized leakage of the confidential data. It provides two extreme views to the database information: completely public or completely hidden. In this paper, we propose an Observation-based Fine Grained Access Control (OFGAC) mechanism based on the Abstract Interpretation framework where data are made accessible at various level of abstraction. In this setting, unauthorized users are not able to infer the exact content of a cell containing confidential information, while they are allowed to get partial information out of it, according to their access rights. Different level of sensitivity of the information correspond to different level of abstraction. In this way, we can tune different parts of the same database content according to different level of abstraction at the same time. The traditional FGAC can be seen as a special case of the OFGAC framework.
引用
收藏
页码:254 / 265
页数:12
相关论文
共 50 条
  • [1] Observation-Based Fine Grained Access Control for XML Documents
    Halder, Raju
    Cortesi, Agostino
    [J]. COMPUTER INFORMATION SYSTEMS - ANALYSIS AND TECHNOLOGIES, 2011, 245 : 267 - 276
  • [3] A fine-grained access control model for relational databases
    Jie Shi
    Hong Zhu
    [J]. Journal of Zhejiang University SCIENCE C, 2010, 11 : 575 - 586
  • [4] A fine-grained access control model for relational databases
    Shi, Jie
    Zhu, Hong
    [J]. JOURNAL OF ZHEJIANG UNIVERSITY-SCIENCE C-COMPUTERS & ELECTRONICS, 2010, 11 (08): : 575 - 586
  • [5] DBMask: Fine-Grained Access Control on Encrypted Relational Databases
    Sarfraz, Muhammad I.
    Nabeel, Mohamed
    Cao, Jianneng
    Bertino, Elisa
    [J]. TRANSACTIONS ON DATA PRIVACY, 2016, 9 (03) : 187 - 214
  • [6] Fine-Grained Access Control in Hybrid Relational-XML Databases
    Sasaki, Taketo
    Fukushima, Takuya
    Park, Daeil
    Toyama, Motomichi
    [J]. 2008 THIRD INTERNATIONAL CONFERENCE ON DIGITAL INFORMATION MANAGEMENT, VOLS 1 AND 2, 2008, : 611 - +
  • [7] Fine-grained Access Control to Web Databases
    Roichman, Alex
    Gudes, Ehud
    [J]. SACMAT'07: PROCEEDINGS OF THE 12TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2007, : 31 - 40
  • [8] Bouncer: Policy-Based Fine Grained Access Control in Large Databases
    Opyrchal, Lukasz
    Cooper, Jeff
    Poyar, Ryan
    Lenahan, Brian
    Zeinner, Daniel
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2011, 5 (02): : 1 - 16
  • [9] A novel approach to fine-grained content-based access control for video databases
    Tran, Nguyen Anh Thy
    Dang, Tran Khanh
    [J]. DEXA 2007: 18TH INTERNATIONAL CONFERENCE ON DATABASE AND EXPERT SYSTEMS APPLICATIONS, PROCEEDINGS, 2007, : 334 - +
  • [10] Towards a fine-grained access control model and mechanisms for semantic databases
    Franzoni, Stefano
    Mazzoleni, Pietro
    Valtolina, Stefano
    Mazzoleni, Pietro
    Bertino, Elisa
    [J]. 2007 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS, 2007, : 993 - +