Controlled Query Evaluation and Inference-Free View Updates

  • Authors:
  • Joachim Biskup;Jens Seiler;Torben Weibert

  • Affiliations:
  • Technische Universität Dortmund, Dortmund, Germany;Technische Universität Dortmund, Dortmund, Germany;Technische Universität Dortmund, Dortmund, Germany

  • Venue:
  • Proceedings of the 23rd Annual IFIP WG 11.3 Working Conference on Data and Applications Security XXIII
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

We extend Controlled Query Evaluation (CQE), an inference control method to enforce confidentiality in static information systems under queries, to updatable databases. Within the framework of the lying approach to CQE, we study user update requests that have to be translated into a new database state. In order to avoid dangerous inferences, some such updates have to be denied even though the new database instance would be compatible with a set of integrity constraints. In contrast, some other updates leading to an incompatible instance should not be denied. We design a control method to resolve this seemingly paradoxical situation and then prove that the general security definitions of CQE and other properties linked to user updates hold.