Managing Data Security in E-Markets through Relationship Driven Access Control

Guoqing Chen,Harry Wang,J. Leon Zhao
DOI: https://doi.org/10.4018/jdm.2012040101
IF: 2.656
2012-01-01
Journal of Database Management
Abstract:Data security in e-markets is vital to maintaining trust among trading partners. In an e-market, companies must share information to improve operational efficiency in their supply chains, while at the same time, access to sensitive information by rival companies should be prevented. In today's highly dynamic business environment, the relationships among companies in e-markets are constantly changing while these relationships determine how company information should be shared with other companies. In this paper, the authors show that existing access control models are not designed for managing data security in e-markets with dynamic company relationships and propose a Relationship Driven Access Control RDAC model to provide a better solution. In particular, the authors design a rule-based approach for managing dynamic company relationships and a secure query processing mechanism to filter shared information based on company relationships. A prototype system is developed to demonstrate and validate the authors' RDAC model.
What problem does this paper attempt to address?