Controlling Information Leakage of Fine-Grained Access Model in DBMSs

Hong Zhu,Jie Shi,Yuanzhen Wang,Yucai Feng
DOI: https://doi.org/10.1109/WAIM.2008.52
2008-01-01
Abstract:The fine-grained access control (FGAC) is important to Web applications. However, it can be circumvented by indirect access such as inferring sensitive data from insensitive data. In the previous FGAC studies, the inference information leakage is not well controlled. In addition, the soundness property, which requires that the results of a query under the FGAC should be the subset of the results of the query without the FGAC over the same database states, can not be held for all SQL statements. Moreover, without soundness information leakage would occur in databases in some situations. In this paper, we divide the approaches which implement FGAC with query modification into two types: the first, the FGAC policy is executed over the results obtained from the query issued by a user; the second, the query issued by a user is executed over the results obtained from the FGAC policy. Then we introduce three types of information leakages of FGAC, which is implemented by using the first approach, and analyze why the existing approaches can not hold soundness for all SQL statements. A novel approach is proposed to control the information leakages and satisfy the soundness property for all SQL statements. Then we implement our approach in DM DBMS with query modification and analyze the test results.
What problem does this paper attempt to address?