Enforcing confidentiality in relational databases by reducing inference control to access control

  • Authors:
  • Joachim Biskup;Jan-Hendrik Lochner

  • Affiliations:
  • Fachbereich Informatik, Universität Dortmund, Dortmund, Germany;Fachbereich Informatik, Universität Dortmund, Dortmund, Germany

  • Venue:
  • ISC'07 Proceedings of the 10th international conference on Information Security
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Security in relational database systems pursues two conflicting interests: confidentiality and availability. In order to effect a compromise between these interests, two techniques have evolved. On the one hand, controlled query evaluation always preserves confidentiality, but leads to undecidable inference problems in general. On the other hand, access control features simple access decisions, but possibly cannot avoid unwanted information flows. This paper introduces a form of access control that, in combination with restricting the query language, results in an efficient access control mechanism under preservation of confidentiality. Moreover, we justify the necessity of our restrictions and give an outlook on how to use our result as building block for a less restrictive but still secure system.