Expression and enforcement of confidentiality policy in active databases

  • Authors:
  • Julien A. Thomas;Nora Cuppens-Boulahia;Frédéric Cuppens

  • Affiliations:
  • Université Européenne de Bretagne, Cesson Sévigné, France;Université Européenne de Bretagne, Cesson Sévigné, France;Université Européenne de Bretagne, Cesson Sévigné, France

  • Venue:
  • Proceedings of the International Conference on Management of Emergent Digital EcoSystems
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Many research works focused on modeling relational database management systems (DBMS) that support multilevel security (MLS) policies. However, most of these previous proposals only consider static aspects of relational databases and do not address dynamicity provided by mechanisms like triggers. Since such mechanisms introduced specific security problems, in particular they create new information flows, it is necessary to extend traditional MLS models designed for relational databases to handle these problems. However, it has been shown in many papers that triggers lack a formal model to support them and so they are not free of ambiguities. To address these theoretical limitations of trigger, our work is based on a formal model that applies MLS policies to active databases. Active databases provide a more expressive and formal framework than triggers. In this paper, we first define an information flow model for active databases. Based on this security model, we then present security requirements that are sufficient to prevent illegal information flows and prove them using the B method.