首页 | 本学科首页   官方微博 | 高级检索  
     


Access control and view generation for provenance graphs
Affiliation:1. Department of Computing, Imperial College London, South Kensington, London SW7 2AZ, UK;2. Department of Primary Care and Public Health Sciences, King’s College London, London SE1 3QD, UK;3. School of Computing Science, Newcastle University, Newcastle NE1 7RU, UK;1. Department of Computer Science and Engineering, National Taiwan Ocean University, Keelung 202, Taiwan;2. Global Business Solution Center, IBM CDL, Taipei 110, Taiwan
Abstract:Data provenance refers to the knowledge about data sources and operations carried out to obtain some piece of data. A provenance-enabled system maintains record of the interoperation of processes across different modules, stages and authorities to capture the full lineage of the resulting data, and typically allows data-focused audits using semantic technologies, such as ontologies, that capture domain knowledge. However, regulating access to captured provenance data is a non-trivial problem, since execution records form complex, overlapping graphs with individual nodes possibly being subject to different access policies. Applying traditional access control to provenance queries can either hide from the user the entire graph with nodes that had access to them denied, reveal too much information, or return a semantically invalid graph. An alternative approach is to answer queries with a new graph that abstracts over the missing nodes and fragments. In this paper, we present TACLP, an access control language for provenance data that supports this approach, together with an algorithm that transforms graphs according to sets of access restrictions. The algorithm produces safe and valid provenance graphs that retain the maximum amount of information allowed by the security model. The approach is demonstrated on an example of restricting access to a clinical trial provenance trace.
Keywords:Provenance  Semantic Web  Access Control Language
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号