Privacy Aware Access Control for Big Data: A Research Roadmap

被引:30
作者
Colombo, Pietro [1 ]
Ferrari, Elena [1 ]
机构
[1] Univ Insubria, Dept Theoret & Appl Sci, I-21100 Varese, Italy
关键词
Big Data; NoSQL datastores; MapReduce systems; Privacy policies; Access control enforcement;
D O I
10.1016/j.bdr.2015.08.001
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Big Data is an emerging phenomenon that is rapidly changing business models and work styles [1]. Big Data platforms allow the storage and analysis of high volumes of data with heterogeneous format from different sources. This integrated analysis allows the derivation of properties and correlations among data that can then be used for a variety of purposes, such as making predictions that can profitably affect decision processes. As a matter of fact, nowadays Big Data analytics are generally considered an asset for making business decisions. Big Data platforms have been specifically designed to support advanced form of analytics satisfying strict performance and scalability requirements. However, no proper consideration has been devoted so far to data protection. Indeed, although the analyzed data often include personal and sensitive information, with relevant threats to privacy implied by the analysis, so far Big Data platforms integrate quite basic form of access control, and no support for privacy policies. Although the potential benefits of data analysis are manifold, the lack of proper data protection mechanisms may prevent the adoption of Big Data analytics by several companies. This motivates the fundamental need to integrate privacy and security awareness into Big Data platforms. In this paper, we do a first step to achieve this ambitious goal, discussing research issues related to the definition of a framework that supports the integration of privacy aware access control features into existing Big Data platforms. (C) 2015 Elsevier Inc. All rights reserved.
引用
收藏
页码:145 / 154
页数:10
相关论文
共 38 条
[1]  
Begoli E., P WICSA ECSA 2012 CO, P177
[2]  
Bertino E, 2005, LECT NOTES COMPUT SC, V3655, P178
[3]   Trust negotiations: Concepts, systems, and languages [J].
Bertino, E ;
Ferrari, E ;
Squicciarini, AC .
COMPUTING IN SCIENCE & ENGINEERING, 2004, 6 (04) :27-34
[4]   A survey of context modelling and reasoning techniques [J].
Bettini, Claudio ;
Brdiczka, Oliver ;
Henricksen, Karen ;
Indulska, Jadwiga ;
Nicklas, Daniela ;
Ranganathan, Anand ;
Riboni, Daniele .
PERVASIVE AND MOBILE COMPUTING, 2010, 6 (02) :161-180
[5]   Purpose based access control for privacy protection in relational database systems [J].
Byun, Ji-Won ;
Li, Ninghui .
VLDB JOURNAL, 2008, 17 (04) :603-619
[6]  
C. S. Alliance, 2012, TOP 10 BIG DAT SEC P
[7]  
Colombo P., 2014, IEEE T DEPENDABLE SE, V11
[8]  
Colombo P., 2015, 23 IT S ADV DAT SYST
[9]   Efficient Enforcement of Action-Aware Purpose-Based Access Control within Relational Database Management Systems [J].
Colombo, Pietro ;
Ferrari, Elena .
IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2015, 27 (08) :2134-2147
[10]   Enforcement of Purpose Based Access Control within Relational Database Management Systems [J].
Colombo, Pietro ;
Ferrari, Elena .
IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2014, 26 (11) :2703-2716