Efficient inference control for open relational queries

  • Authors:
  • Joachim Biskup;Sven Hartmann;Sebastian Link;Jan-Hendrik Lochner

  • Affiliations:
  • Fakultät für Informatik, TU Dortmund, Dortmund, Germany;Institut für Informatik, Technische Universität Clausthal, Germany;School of Information Management, Victoria University of Wellington, New Zealand;Fakultät für Informatik, TU Dortmund, Dortmund, Germany

  • Venue:
  • DBSec'10 Proceedings of the 24th annual IFIP WG 11.3 working conference on Data and applications security and privacy
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

We present a control mechanism for preserving confidentiality in relational databases under open queries. This mechanism is based on a reduction of costly inference control to efficient access control that has recently been developed for closed database queries. Our approach guarantees that secrets being declared in form of a confidentiality policy are not disclosed to database users even if they utilize their a priori knowledge to draw inferences. It turns out that there is no straightforward transition from the approach for closed queries to open queries. We show, however, that hiding the confidentiality policy from database users is sufficient to preserve confidentiality. Moreover, we propose an algorithmic implementation of the control mechanism.