A formal study of collaborative access control in distributed datalog

Serge Abiteboul 1, 2 Pierre Bourhis 3 Victor Vianu 4, 2
2 DAHU - Verification in databases
LSV - Laboratoire Spécification et Vérification [Cachan], ENS Cachan - École normale supérieure - Cachan, Inria Saclay - Ile de France, CNRS - Centre National de la Recherche Scientifique : UMR8643
3 LINKS - Linking Dynamic Data
Inria Lille - Nord Europe, CRIStAL - Centre de Recherche en Informatique, Signal et Automatique de Lille (CRIStAL) - UMR 9189
Abstract : We formalize and study a declaratively specified collaborative access control mechanism for data dissemination in a distributed environment. Data dissemination is specified using distributed datalog. Access control is also defined by datalog-style rules, at the relation level for extensional relations, and at the tuple level for intensional ones, based on the derivation of tuples. The model also includes a mechanism for " declassifying " data, that allows circumventing overly restrictive access control. We consider the complexity of determining whether a peer is allowed to access a given fact, and address the problem of achieving the goal of disseminating certain information under some access control policy. We also investigate the problem of information leakage, which occurs when a peer is able to infer facts to which the peer is not allowed access by the policy. Finally, we consider access control extended to facts equipped with provenance information, motivated by the many applications where such information is required. We provide semantics for access control with provenance, and establish the complexity of determining whether a peer may access a given fact together with its provenance. This work is motivated by the access control of the Webdamlog system, whose core features it formalizes.
Type de document :
Communication dans un congrès
Wim Martens ; Thomas Zeume. ICDT 2016 - 19th International Conference on Database Theory , Mar 2016, Bordeaux, France. 〈http://drops.dagstuhl.de/opus/portals/lipics/index.php?semnr=16002〉
Liste complète des métadonnées

Littérature citée [33 références]  Voir  Masquer  Télécharger

https://hal.inria.fr/hal-01290497
Contributeur : Serge Abiteboul <>
Soumis le : vendredi 18 mars 2016 - 11:51:12
Dernière modification le : jeudi 11 janvier 2018 - 06:27:32
Document(s) archivé(s) le : dimanche 19 juin 2016 - 23:40:38

Fichier

icdt16.pdf
Fichiers produits par l'(les) auteur(s)

Identifiants

  • HAL Id : hal-01290497, version 1

Citation

Serge Abiteboul, Pierre Bourhis, Victor Vianu. A formal study of collaborative access control in distributed datalog. Wim Martens ; Thomas Zeume. ICDT 2016 - 19th International Conference on Database Theory , Mar 2016, Bordeaux, France. 〈http://drops.dagstuhl.de/opus/portals/lipics/index.php?semnr=16002〉. 〈hal-01290497〉

Partager

Métriques

Consultations de la notice

372

Téléchargements de fichiers

92