Data integration in presence of authorization policies

Mehdi Haddad 1 Mohand-Said Hacid 1 Robert Laurini 1
1 BD - Base de Données
LIRIS - Laboratoire d'InfoRmatique en Image et Systèmes d'information
Abstract : Information is more and more stored over distributed sources. A simple access to information in these sources requires a single access point. Data integration methods are designed to provide this kind of access by allowing to specify a mediator between the users and the sources. From an access control point of view, the question is how to specify access control of a system built on top of distributed data sources. Each source specifies and enforces its own policies. So, an access control enforced at the mediator level has to preserve the local access controls (of the sources). In this paper, we investigate an approach allowing to derive (i.e., factorization) the access control policies that should be attached and enforced at the mediator level. The proposed approach is illustrated on the relational data model as a reference framework. The approach ensures that the local policies are preserved at the mediator level.
