Don't Be a Tattle-Tale: Preventing Leakages through Data Dependencies on Access Control Protected Data

Don't Be a Tattle-Tale: Preventing Leakages through Data Dependencies on Access Control Protected Data
复制标题

DOI:
10.14778/3551793.3551805
复制
发表时间:
2022-07
期刊:
Proc. VLDB Endow.
影响因子:
--
通讯作者:
Primal Pappachan;Shufan Zhang;Xi He;S. Mehrotra
Primal Pappachan;Shufan Zhang;Xi He;S. Mehrotra
中科院分区:
其他
文献类型:
--
作者:
Primal Pappachan;Shufan Zhang;Xi He;S. Mehrotra

文献摘要

相似文献

我们研究的问题,回答查询时(部分)的数据可能是敏感的,不应该被泄露给查询。简单地将计算限制在数据的非敏感部分可能会通过基于数据依赖性的推断泄漏敏感数据。虽然在文献中已经研究了查询处理期间来自数据依赖性的推理控制,但是现有的解决方案要么检测和拒绝导致泄漏的查询,要么使用仅保护敏感数据的精确重建的弱安全模型。在本文中,我们采用了一个更强大的安全模型的基础上完全否认,防止敏感数据的任何信息被推断从查询答案。我们确定了可以实现完全可否认性的条件,并开发了一种高效的算法,可以在查询处理过程中最低限度地隐藏非敏感单元格,以实现完全可否认性。我们的实验表明,我们的方法是实用的和规模的敏感数据的比例增加,以及,增加数据库的大小。
We study the problem of answering queries when (part of) the data may be sensitive and should not be leaked to the querier. Simply restricting the computation to non-sensitive part of the data may leak sensitive data through inference based on data dependencies. While inference control from data dependencies during query processing has been studied in the literature, existing solution either detect and deny queries causing leakage, or use a weak security model that only protects against exact reconstruction of the sensitive data. In this paper, we adopt a stronger security model based on full deniability that prevents any information about sensitive data to be inferred from query answers. We identify conditions under which full deniability can be achieved and develop an efficient algorithm that minimally hides non-sensitive cells during query processing to achieve full deniability. We experimentally show that our approach is practical and scales to increasing proportion of sensitive data, as well as, to increasing database size.