Purpose based access control for privacy protection in relational database systems

被引:0
|
作者
Ji-Won Byun
Ninghui Li
机构
[1] Purdue University,CERIAS and Department of Computer Science
来源
The VLDB Journal | 2008年 / 17卷
关键词
Privacy; Access control; Purpose; Private data management;
D O I
暂无
中图分类号
学科分类号
摘要
In this article, we present a comprehensive approach for privacy preserving access control based on the notion of purpose. In our model, purpose information associated with a given data element specifies the intended use of the data element. A key feature of our model is that it allows multiple purposes to be associated with each data element and also supports explicit prohibitions, thus allowing privacy officers to specify that some data should not be used for certain purposes. An important issue addressed in this article is the granularity of data labeling, i.e., the units of data with which purposes can be associated. We address this issue in the context of relational databases and propose four different labeling schemes, each providing a different granularity. We also propose an approach to represent purpose information, which results in low storage overhead, and we exploit query modification techniques to support access control based on purpose information. Another contribution of our work is that we address the problem of how to determine the purpose for which certain data are accessed by a given user. Our proposed solution relies on role-based access control (RBAC) models as well as the notion of conditional role which is based on the notions of role attribute and system attribute.
引用
收藏
页码:603 / 619
页数:16
相关论文
共 50 条
  • [1] Purpose based access control for privacy protection in relational database systems
    Byun, Ji-Won
    Li, Ninghui
    VLDB JOURNAL, 2008, 17 (04): : 603 - 619
  • [2] Purpose based Access Control for Privacy Protection in Object Relational Database Systems
    Shyni, C. Emilin C.
    Swamynathan, S.
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON DATA STORAGE AND DATA ENGINEERING (DSDE 2010), 2010, : 90 - 94
  • [3] Enforcement of Purpose Based Access Control within Relational Database Management Systems
    Colombo, Pietro
    Ferrari, Elena
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2014, 26 (11) : 2703 - 2716
  • [4] Researches on Integrating Database Access Control and Privacy Protection
    Yu Yonghong
    FIFTH INTERNATIONAL CONFERENCE ON INFORMATION ASSURANCE AND SECURITY, VOL 2, PROCEEDINGS, 2009, : 330 - 333
  • [5] Efficient Enforcement of Action-Aware Purpose-Based Access Control within Relational Database Management Systems
    Colombo, Pietro
    Ferrari, Elena
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2015, 27 (08) : 2134 - 2147
  • [6] Efficient Enforcement of Action-aware Purpose-based Access Control within Relational Database Management Systems
    Colombo, Pietro
    Ferrari, Elena
    2016 32ND IEEE INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE), 2016, : 1516 - 1517
  • [7] Access control of XML documents in relational database systems
    Tan, KL
    Lee, ML
    Wang, Y
    IC'2001: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON INTERNET COMPUTING, VOLS I AND II, 2001, : 185 - 191
  • [8] Privacy Protection Method Based on Access Control
    Qiao, Xin
    Wang, Lixiaoyang
    Qin, Bo
    Chen, Hong
    Zhao, Suyun
    2018 ASIA-PACIFIC SIGNAL AND INFORMATION PROCESSING ASSOCIATION ANNUAL SUMMIT AND CONFERENCE (APSIPA ASC), 2018, : 254 - 259
  • [9] Modern Physical Access Control Systems and Privacy Protection
    Dzurenda, Petr
    Hajny, Jan
    Zeman, Vaclav
    Vrba, Kamil
    2015 38TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS AND SIGNAL PROCESSING (TSP), 2015, : 1 - 5
  • [10] Integrated privacy protection and access control over outsourced database services
    Yu, Yonghong
    Bai, Wenyang
    Journal of Computational Information Systems, 2010, 6 (08): : 2767 - 2777