DocumentCode :
408326
Title :
A constraint-based query modification engine for retrofitting COTS DBMS´s
Author :
Garuba, Moses ; Langrin, Ronald ; Burge, Legand
Author_Institution :
Dept. of Syst. & Comput. Sci., Howard Univ., Washington, DC, USA
Volume :
1
fYear :
2004
fDate :
5-7 April 2004
Firstpage :
551
Abstract :
Models have been proposed to ensure the secrecy of data using various strategies. A number of these models however do not adequately address the problem of inference. This paper describes the design and implementation of a prototype that uses query modification along with security constraints to accurately return the proper information to the user whilst preventing unauthorized disclosure of data. The strategy works by augmenting a user´s query with security constraints to ensure that the modified query is correct and safe in relation to the user´s clearance level. The prototype is an implementation and extension of the query modification technique proposed by Keefe.
Keywords :
authorisation; constraint handling; data privacy; database management systems; query processing; software packages; COTS DBMS; data secrecy; inference problem; query modification engine; security constraints; unauthorized data disclosure; Access control; Banking; Data security; Engines; Information security; Multilevel systems; Personnel; Protection; Prototypes; Relational databases;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Technology: Coding and Computing, 2004. Proceedings. ITCC 2004. International Conference on
Print_ISBN :
0-7695-2108-8
Type :
conf
DOI :
10.1109/ITCC.2004.1286521
Filename :
1286521
Link To Document :
بازگشت