Access control to materialized views: an inference-based approach

  • Authors:
  • Sarah Nait Bahloul;Emmanuel Coquery;Mohand-Saïd Hacid

  • Affiliations:
  • Université de Lyon, CNRS, LIRIS, France;Université de Lyon, CNRS, LIRIS, France;Université de Lyon, CNRS, LIRIS, France

  • Venue:
  • Proceedings of the 2011 Joint EDBT/ICDT Ph.D. Workshop
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

Ensuring security of data is one of the fundamental needs of people. In this context, issues related to confidentiality, integrity and availability of the data arise with a crucial importance, whether in economic, legal or medical domains. Standards covering fine-grained access control were proposed and adopted to control access to data through queries. In this paper, we propose a novel approach to facilitate the administration of access control rules to ensure the confidentiality of data at the level of materialized views. Several techniques and models have been proposed to control access to databases, but to our knowledge the problem of automatically generating from access control rules defined over base relations the applicable access control rules needed to control materialized views is not investigated. We are investigating this problem by resorting to an adaptation of query rewriting techniques. We choose to express fine-grained access control through authorization views. This paper mainly discusses the problem of automatically ensuring confidentiality of materialized views based on basic access control rules, and identifies formal tools to tackle the problem.