Tuple-Based Access Control: a Provenance-Based Information Flow Control for Relational Data - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2015

Tuple-Based Access Control: a Provenance-Based Information Flow Control for Relational Data

Romuald Thion
François Lesueur
Meriam Talbi
  • Fonction : Auteur
  • PersonId : 970275

Résumé

This paper proposes a flexible control framework for relational personal data that enforces data orig-inators' dissemination policies. Inspired by the sticky policy paradigm and mandatory access control, dissemination policies are linked with atomic data and are combined when different pieces of data are merged. The background setting of relational provenance guarantees that the policy combining operations behave accordingly to the operations carried out on the data. We show that the framework can capture a large class of policies similar to those of lattice-based access control models and that it can be integrated seamlessly into relational database management systems. In particular, we define a path oriented dissemination control model where policies define authorized chains of transfers between databases. Promising ongoing research work include the generalization of the theoretical framework to more expressive query languages including aggregation and difference operators as well as experiments on secure tokens.
Fichier principal
Vignette du fichier
secsac15.pdf (322.54 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-01192900 , version 1 (15-09-2015)

Identifiants

Citer

Romuald Thion, François Lesueur, Meriam Talbi. Tuple-Based Access Control: a Provenance-Based Information Flow Control for Relational Data. SAC '15 Proceedings of the 30th Annual ACM Symposium on Applied Computing, ACM, Apr 2015, Salamanca, Spain. pp.2165-2170, ⟨10.1145/2695664.2695758⟩. ⟨hal-01192900⟩
168 Consultations
232 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More