Purpose based access control for privacy protection in relational database systems

被引:0
作者
Ji-Won Byun
Ninghui Li
机构
[1] Purdue University,CERIAS and Department of Computer Science
来源
The VLDB Journal | 2008年 / 17卷
关键词
Privacy; Access control; Purpose; Private data management;
D O I
暂无
中图分类号
学科分类号
摘要
In this article, we present a comprehensive approach for privacy preserving access control based on the notion of purpose. In our model, purpose information associated with a given data element specifies the intended use of the data element. A key feature of our model is that it allows multiple purposes to be associated with each data element and also supports explicit prohibitions, thus allowing privacy officers to specify that some data should not be used for certain purposes. An important issue addressed in this article is the granularity of data labeling, i.e., the units of data with which purposes can be associated. We address this issue in the context of relational databases and propose four different labeling schemes, each providing a different granularity. We also propose an approach to represent purpose information, which results in low storage overhead, and we exploit query modification techniques to support access control based on purpose information. Another contribution of our work is that we address the problem of how to determine the purpose for which certain data are accessed by a given user. Our proposed solution relies on role-based access control (RBAC) models as well as the notion of conditional role which is based on the notions of role attribute and system attribute.
引用
收藏
页码:603 / 619
页数:16
相关论文
共 50 条
  • [1] Purpose based access control for privacy protection in relational database systems
    Byun, Ji-Won
    Li, Ninghui
    VLDB JOURNAL, 2008, 17 (04) : 603 - 619
  • [2] Purpose based Access Control for Privacy Protection in Object Relational Database Systems
    Shyni, C. Emilin C.
    Swamynathan, S.
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON DATA STORAGE AND DATA ENGINEERING (DSDE 2010), 2010, : 90 - 94
  • [3] Purpose fusion: The risk purpose based privacy-aware data access control
    Liu Y.-M.
    Zhou H.-F.
    Wang Z.-H.
    Wang W.
    Jisuanji Xuebao/Chinese Journal of Computers, 2010, 33 (08): : 1339 - 1348
  • [4] Researches on Integrating Database Access Control and Privacy Protection
    Yu Yonghong
    FIFTH INTERNATIONAL CONFERENCE ON INFORMATION ASSURANCE AND SECURITY, VOL 2, PROCEEDINGS, 2009, : 330 - 333
  • [5] Modern Physical Access Control Systems and Privacy Protection
    Dzurenda, Petr
    Hajny, Jan
    Zeman, Vaclav
    Vrba, Kamil
    2015 38TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS AND SIGNAL PROCESSING (TSP), 2015, : 1 - 5
  • [6] Location Based Privacy Preserving Access Control for Relational Data
    Lakadkutta, Ahmed H. I.
    Mante, R. V.
    2016 IEEE INTERNATIONAL CONFERENCE ON RECENT TRENDS IN ELECTRONICS, INFORMATION & COMMUNICATION TECHNOLOGY (RTEICT), 2016, : 2083 - 2087
  • [7] AuthPrivacyChain: A Blockchain-Based Access Control Framework With Privacy Protection in Cloud
    Yang, Caixia
    Tan, Liang
    Shi, Na
    Xu, Bolei
    Cao, Yang
    Yu, Keping
    IEEE ACCESS, 2020, 8 : 70604 - 70615
  • [8] Dynamic permission access control model based on privacy protection
    Qikun Zhang
    Liang Zhu
    Kunyuan Zhao
    Yimeng Wu
    Baohua Jin
    Jianyong Li
    Yinghui Meng
    Sikang Hu
    Telecommunication Systems, 2022, 81 : 191 - 205
  • [9] Dynamic permission access control model based on privacy protection
    Zhang, Qikun
    Zhu, Liang
    Zhao, Kunyuan
    Wu, Yimeng
    Jin, Baohua
    Li, Jianyong
    Meng, Yinghui
    Hu, Sikang
    TELECOMMUNICATION SYSTEMS, 2022, 81 (02) : 191 - 205
  • [10] Purpose-Based Access Control Policies and Conflicting Analysis
    Wang, Hua
    Sun, Lili
    Varadharajan, Vijay
    SECURITY AND PRIVACY - SILVER LININGS IN THE CLOUD, 2010, 330 : 217 - +