检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:刘逸敏[1,2] 王智慧[1] 周皓峰[1] 汪卫[1]
机构地区:[1]复旦大学计算机科学技术学院,上海200433 [2]第二军医大学第三附属医院信息科,上海200438
出 处:《计算机科学与探索》2010年第3期222-230,共9页Journal of Frontiers of Computer Science and Technology
基 金:国家科技重大专项课题No.2008ZX10207;高等学校博士学科点专项科研基金No.200802461146~~
摘 要:随着各行业对隐私数据访问指导规范的颁布,如HIPAA、OECD,隐私数据的访问控制逐渐成为隐私数据管理领域的一个研究热点。关系数据库中基于角色和视图的访问控制机制实现了对用户访问权限的控制,但是不能解决面向隐私的访问控制问题。隐私数据描述的关键元素是具有层次结构的data purpose,而已有的基于data purpose的访问控制模型具有隐私策略冗余和没有考虑返回结果最大化的缺点。提出了一种新的基于purpose的隐私数据访问控制机制(R-PAACEE),通过对data purpose的概念分层,用二元组数据结构描述data purpose的层次数据模式,减少了隐私策略冗余,进而提出分离隐私与非隐私属性的查询重写算法,实现了查询返回结果的最大化。实验结果表明,针对隐私数据的查询访问,已加载R-PAACEE的数据库管理系统能够获得较好的查询效率。With the release of the privacy data access guidelines by industries, such as HIPAA and OECD guidelines, the access control of privacy data has recently become a hot research topic in the area of privacy data management. The role-based access control mechanism and view-based access control mechanism in a relational database only support the controls for users' access permissions, but they don't solve the problems of privacyaware access control. The key elements for describing privacy data are the hierarchical structure of data purpose. Several purpose-based access control models presented currently have two shortcomings: The redundancy of priva- cy policies and the query results not maximized. This paper proposes a novel purpose-based relational database access control model R-PAACEE (privacy-aware access control enforcement engine), which can reduce the redundancy of privacy policies by constructing the concept hierarchy of privacy policies and describing them with ordered tuples. The paper also presents a query-rewritten algorithm for separating the private and non-private attributes, which can maximize the query results. The experimental results show that for a query related to privacy data, a database management system with R-PAACEE can achieve good query performance.
分 类 号:TP311.13[自动化与计算机技术—计算机软件与理论]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.126