Purpose based access control for privacy protection in relational database systems

被引:0
作者
Ji-Won Byun
Ninghui Li
机构
[1] Purdue University,CERIAS and Department of Computer Science
来源
The VLDB Journal | 2008年 / 17卷
关键词
Privacy; Access control; Purpose; Private data management;
D O I
暂无
中图分类号
学科分类号
摘要
In this article, we present a comprehensive approach for privacy preserving access control based on the notion of purpose. In our model, purpose information associated with a given data element specifies the intended use of the data element. A key feature of our model is that it allows multiple purposes to be associated with each data element and also supports explicit prohibitions, thus allowing privacy officers to specify that some data should not be used for certain purposes. An important issue addressed in this article is the granularity of data labeling, i.e., the units of data with which purposes can be associated. We address this issue in the context of relational databases and propose four different labeling schemes, each providing a different granularity. We also propose an approach to represent purpose information, which results in low storage overhead, and we exploit query modification techniques to support access control based on purpose information. Another contribution of our work is that we address the problem of how to determine the purpose for which certain data are accessed by a given user. Our proposed solution relies on role-based access control (RBAC) models as well as the notion of conditional role which is based on the notions of role attribute and system attribute.
引用
收藏
页码:603 / 619
页数:16
相关论文
共 50 条
  • [31] XML Access Control: Mapping XACML Policies to Relational Database Tables
    El-Aziz, Abd El-Aziz Ahmed Abd
    Kannanl, Arputharaj
    INTERNATIONAL ARAB JOURNAL OF INFORMATION TECHNOLOGY, 2014, 11 (06) : 532 - 539
  • [32] An Integrated Privacy Preserving Attribute Based Access Control Framework
    Xu, Runhua
    Joshi, James B. D.
    PROCEEDINGS OF 2016 IEEE 9TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD), 2016, : 68 - 76
  • [33] Web-Based Sharing of Electrocardiograms: Privacy and Access Control
    Yuan, Shizhong
    Wei, Daming
    Xu, Weimin
    Shen, Wenfeng
    WISM: 2009 INTERNATIONAL CONFERENCE ON WEB INFORMATION SYSTEMS AND MINING, PROCEEDINGS, 2009, : 82 - +
  • [34] A temporal access control mechanism for database systems
    Bertino, E
    Bettini, C
    Ferrari, E
    Samarati, P
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 1996, 8 (01) : 67 - 80
  • [35] Privacy-Aware Role-Based Access Control
    Ni, Qun
    Bertino, Elisa
    Lobo, Jorge
    Brodie, Carolyn
    Karat, Clare-Marie
    Karat, John
    Trombetta, Alberto
    ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2010, 13 (03)
  • [36] A Framework for Expressing and Enforcing Purpose-Based Privacy Policies
    Jafari, Mohammad
    Safavi-Naini, Reihaneh
    Fong, Philip W. L.
    Barker, Ken
    ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2014, 17 (01)
  • [37] Towards Application-Layer Purpose-Based Access Control
    Pallas, Frank
    Ulbricht, Max-R
    Tai, Stefan
    Peikert, Thomas
    Reppenhagen, Marcel
    Wenzel, Daniel
    Wille, Paul
    Wolf, Karl
    PROCEEDINGS OF THE 35TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING (SAC'20), 2020, : 1288 - 1296
  • [38] A privacy protection method for health care big data management based on risk access control
    Shi, Mingyue
    Jiang, Rong
    Hu, Xiaohan
    Shang, Jingwei
    HEALTH CARE MANAGEMENT SCIENCE, 2020, 23 (03) : 427 - 442
  • [39] A Novel Attribute-based Access Control System for Fine-Grained Privacy Protection
    Son, Ha Xuan
    Nguyen Minh Hoang
    PROCEEDINGS OF 2019 THE 3RD INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY (ICCSP 2019) WITH WORKSHOP 2019 THE 4TH INTERNATIONAL CONFERENCE ON MULTIMEDIA AND IMAGE PROCESSING (ICMIP 2019), 2019, : 76 - 80
  • [40] A role-involved purpose-based access control model
    Md. Enamul Kabir
    Hua Wang
    Elisa Bertino
    Information Systems Frontiers, 2012, 14 : 809 - 822