Extending SQL to allow the active usage of purposes

  • Authors:
  • Wynand van Staden;Martin S. Olivier

  • Affiliations:
  • Information and Computer Security Architecture Research Group, University of Pretoria, Pretoria, South Africa;Information and Computer Security Architecture Research Group, University of Pretoria, Pretoria, South Africa

  • Venue:
  • TrustBus'06 Proceedings of the Third international conference on Trust, Privacy, and Security in Digital Business
  • Year:
  • 2006

Quantified Score

Hi-index 0.01

Visualization

Abstract

The protection of private information revolves around the protection of data by making use of purposes. These purposes indicate why data is stored, and what the data will be used for (referred to as specification/verification phases). In this article, the active specification of purposes during access requests is considered. In particular it is argued that the subject that wishes to get access to data should explicitly specify their reason for wanting the data; as opposed to verification taking place by implicit examination of the subject’s profile. To facilitate this active specification extensions to the SQL data manipulation language is considered.