首页> 外文期刊>The VLDB journal >Purpose based access control for privacy protection in relational database systems
【24h】

Purpose based access control for privacy protection in relational database systems

机译:基于目的的访问控制,用于关系数据库系统中的隐私保护

获取原文
获取原文并翻译 | 示例
           

摘要

In this article, we present a comprehensive approach for privacy preserving access control based on the notion of purpose. In our model, purpose information associated with a given data element specifies the intended use of the data element. A key feature of our model is that it allows multiple purposes to be associated with each data element and also supports explicit prohibitions, thus allowing privacy officers to specify that some data should not be used for certain purposes. An important issue addressed in this article is the granularity of data labeling, i.e., the units of data with which purposes can be associated. We address this issue in the context of relational databases and propose four different labeling schemes, each providing a different granularity. We also propose an approach to represent purpose information, which results in low storage overhead, and we exploit query modification techniques to support access control based on purpose information. Another contribution of our work is that we address the problem of how to determine the purpose for which certain data are accessed by a given user. Our proposed solution relies on role-based access control (RBAC) models as well as the notion of conditional role which is based on the notions of role attribute and system attribute.
机译:在本文中,我们提出了一种基于目的概念的隐私保护访问控制的综合方法。在我们的模型中,与给定数据元素相关的目的信息指定了数据元素的预期用途。我们模型的一个关键特征是,它允许将多个目的与每个数据元素相关联,并且还支持显式禁止,从而使隐私保护人员可以指定不应将某些数据用于某些目的。本文解决的一个重要问题是数据标记的粒度,即可以与用途关联的数据单元。我们在关系数据库的背景下解决了这个问题,并提出了四种不同的标记方案,每种方案提供了不同的粒度。我们还提出了一种表示目的信息的方法,这导致了较低的存储开销,并且我们利用查询修改技术来支持基于目的信息的访问控制。我们工作的另一个贡献是,我们解决了如何确定给定用户访问某些数据的目的的问题。我们提出的解决方案依赖于基于角色的访问控制(RBAC)模型以及基于角色属性和系统属性的条件角色概念。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号