Purpose based access control for privacy protection in relational database systems

被引:0
作者
Ji-Won Byun
Ninghui Li
机构
[1] Purdue University,CERIAS and Department of Computer Science
来源
The VLDB Journal | 2008年 / 17卷
关键词
Privacy; Access control; Purpose; Private data management;
D O I
暂无
中图分类号
学科分类号
摘要
In this article, we present a comprehensive approach for privacy preserving access control based on the notion of purpose. In our model, purpose information associated with a given data element specifies the intended use of the data element. A key feature of our model is that it allows multiple purposes to be associated with each data element and also supports explicit prohibitions, thus allowing privacy officers to specify that some data should not be used for certain purposes. An important issue addressed in this article is the granularity of data labeling, i.e., the units of data with which purposes can be associated. We address this issue in the context of relational databases and propose four different labeling schemes, each providing a different granularity. We also propose an approach to represent purpose information, which results in low storage overhead, and we exploit query modification techniques to support access control based on purpose information. Another contribution of our work is that we address the problem of how to determine the purpose for which certain data are accessed by a given user. Our proposed solution relies on role-based access control (RBAC) models as well as the notion of conditional role which is based on the notions of role attribute and system attribute.
引用
收藏
页码:603 / 619
页数:16
相关论文
共 50 条
  • [21] Adaptive access control method for SaaS privacy protection
    Fan D.-J.
    Huang Z.-Q.
    Cao Y.
    Jilin Daxue Xuebao (Gongxueban)/Journal of Jilin University (Engineering and Technology Edition), 2023, 53 (10): : 2897 - 2908
  • [22] Accuracy-Constrained Privacy-Preserving Access Control Mechanism for Relational Data
    Pervaiz, Zahid
    Aref, Walid G.
    Ghafoor, Arif
    Prabhu, Nagabhushana
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2014, 26 (04) : 795 - 807
  • [23] A CONDITIONAL ROLE-INVOLVED PURPOSE-BASED ACCESS CONTROL MODEL
    Kabir, Md. Enamul
    Wang, Hua
    Bertino, Elisa
    JOURNAL OF ORGANIZATIONAL COMPUTING AND ELECTRONIC COMMERCE, 2011, 21 (01) : 71 - 91
  • [24] Access Control for Privacy Protection for Dynamic and Correlated Databases
    Zhu, Nafei
    Zhang, Min
    Feng, Dengguo
    He, Jingsha
    2015 IEEE INTERNATIONAL CONFERENCE ON SMART CITY/SOCIALCOM/SUSTAINCOM (SMARTCITY), 2015, : 775 - 779
  • [25] Security and Privacy Frameworks for Access Control Big Data Systems
    Centonze, Paolina
    CMC-COMPUTERS MATERIALS & CONTINUA, 2019, 59 (02): : 361 - 374
  • [26] Privacy-aware Role Based Access Control
    Ni, Qun
    Trombetta, Alberto
    Bertino, Elisa
    Lobo, Jorge
    SACMAT'07: PROCEEDINGS OF THE 12TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2007, : 41 - 50
  • [27] Use of Purpose and Role Based Access Control Mechanisms to Protect Data Within RDBMS
    Patil, Suraj Krishna
    Sagare, Sandipkumar Chandrakant
    Shelar, Alankar Shantaram
    INTERNATIONAL JOURNAL OF SOFTWARE INNOVATION, 2020, 8 (01) : 82 - 91
  • [28] Privacy Protection of Fingerprint Database
    Li, Sheng
    Kot, Alex C.
    IEEE SIGNAL PROCESSING LETTERS, 2011, 18 (02) : 115 - 118
  • [29] Access-control-based Efficient Privacy Protection Method for Social Networking Services
    Jang, Yu-Jon
    Kwak, Jin
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2013, 7 (05): : 305 - 314
  • [30] On Usage Control in Relational Database Management Systems Obligations and Their Enforcement in Joining Datasets
    Bargh, Mortaza S.
    Vink, Marco
    Choenni, Sunil
    ICISSP: PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2017, : 190 - 201