Skip to Main Content (Press Enter)

Logo UNINSUBRIA
  • ×
  • Home
  • Corsi
  • Insegnamenti
  • Professioni
  • Persone
  • Pubblicazioni
  • Strutture
  • Terza Missione
  • Attività
  • Competenze

UNI-FIND
Logo UNINSUBRIA

|

UNI-FIND

uninsubria.it
  • ×
  • Home
  • Corsi
  • Insegnamenti
  • Professioni
  • Persone
  • Pubblicazioni
  • Strutture
  • Terza Missione
  • Attività
  • Competenze
  1. Pubblicazioni

An extended access control mechanism exploiting data dependencies

Articolo
Data di Pubblicazione:
2017
Abstract:
In general, access control mechanisms in DBMSs ensure that users access only those portions of data for which they have authorizations, according to a predefined set of access control policies. However, it has been shown that access control mechanisms might be not enough. A clear example is the inference problem due to functional dependencies, which might allow a user to discover unauthorized data by exploiting authorized data. In this paper, we wish to investigate data dependencies (e.g., functional dependencies, foreign key constraints, and knowledge-based implications) from a different perspective. In particular, the aim was to investigate data dependencies as a mean for increasing the DBMS utility, that is, the number of queries that can be safely answered, rather than as channels for releasing sensitive data. We believe that, under given circumstances, this unauthorized release may give more benefits than issues. As such, we present a query rewriting technique capable of extending defined access control policies by exploiting data dependencies, in order to authorize unauthorized but inferable data.
Tipologia CRIS:
Articolo su Rivista
Keywords:
Data dependencies; Discretionary access control; Functional dependencies; Query rewriting; Software; Information Systems; Safety, Risk, Reliability and Quality; Computer Networks and Communications
Elenco autori:
Albertini, DAVIDE ALBERTO; Carminati, Barbara; Ferrari, Elena
Autori di Ateneo:
CARMINATI BARBARA
FERRARI ELENA
Link alla scheda completa:
https://irinsubria.uninsubria.it/handle/11383/2062590
Pubblicato in:
INTERNATIONAL JOURNAL OF INFORMATION SECURITY
Journal
  • Dati Generali

Dati Generali

URL

http://springerlink.metapress.com/app/home/journal.asp?wasp=g3t6cbhqrp4jyjcehg71&referrer=parent&backto=linkingpublicationresults,1:107927,1
  • Accessibilità
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.1.0