Abstract : We present a control mechanism for preserving confidentiality in relational databases under open queries. This mechanism is based on a reduction of costly inference control to efficient access control that has recently been developed for closed database queries. Our approach guarantees that secrets being declared in form of a confidentiality policy are not disclosed to database users even if they utilize their a priori knowledge to draw inferences. It turns out that there is no straightforward transition from the approach for closed queries to open queries. We show, however, that hiding the confidentiality policy from database users is sufficient to preserve confidentiality. Moreover, we propose an algorithmic implementation of the control mechanism.
https://hal.inria.fr/hal-01056690 Contributor : Hal IfipConnect in order to contact the contributor Submitted on : Wednesday, August 20, 2014 - 1:23:42 PM Last modification on : Wednesday, February 5, 2020 - 4:26:14 PM Long-term archiving on: : Thursday, November 27, 2014 - 11:48:48 AM
Joachim Biskup, Sven Hartmann, Sebastian Link, Jan-Hendrik Lochner. Efficient Inference Control for Open Relational Queries. 24th Annual IFIP WG 11.3 Working Conference on Data and Applications Security and Privacy (DBSEC), Jun 2010, Rome, Italy. pp.162-176, ⟨10.1007/978-3-642-13739-6_11⟩. ⟨hal-01056690⟩