DocumentCode :
1791617
Title :
Content-Based Access Control: Use data content to assist access control for large-scale content-centric databases
Author :
Wenrong Zeng ; Yuhao Yang ; Bo Luo
Author_Institution :
Dept. of Electr. Eng. & Comput. Sci., Univ. of Kansas, Lawrence, KS, USA
fYear :
2014
fDate :
27-30 Oct. 2014
Firstpage :
701
Lastpage :
710
Abstract :
In conventional database access control models, access control policies are explicitly specified for each role against each data object. In large-scale content-centric data sharing, it might be difficult to explicitly identify accessible records for each role/user, especially when the semantic content of data is expected to play a role in access decisions. As a result, users are often over-privileged, and ex post facto auditing is enforced to detect misuse of the privileges. Unfortunately, it is usually difficult to reverse the damage, as (large amount of) data has been disclosed already. In this paper, we introduce Content-Based Access Control (CBAC), an innovative access control model for content-centric information sharing. CBAC is expected to be deployed on top of Role-Based Access Control (RBAC) or Multi-level Security (MLS), in the application scenarios where RBAC and MLS will give excessive access rights. As a complement to conventional access control models, the CBAC model makes access control decisions based on the content similarity. In CBAC, each user is allowed by an MLS or RBAC rule to access a large set of data objects, while the CBAC rule imposes an additional layer of restrictions that the user could only access “a subset” of the designated records. The boundary of the subset is dynamically determined by the textual content of data objects. We then present an enforcement mechanism for CBAC that exploits Oracle´s Virtual Private Database (VPD). To further improve the performance of the proposed approach, we introduce a content-based blocking mechanism to improve the efficiency of CBAC enforcement. We also develop a content annotation mechanism for more accurate textual content matching for short text snippets. Experimental results show that CBAC makes reasonable access control decisions with a small overhead.
Keywords :
authorisation; database management systems; text analysis; CBAC enforcement efficiency improvement; CBAC model; MLS; Oracle virtual private database; RBAC; VPD; access control decision making; access rights; application scenarios; content annotation mechanism; content similarity; content-based access control policies; content-based blocking mechanism; content-centric information sharing; data content; data object; data objects; database access control models; designated records; enforcement mechanism; ex-post facto auditing; explicit accessible record identification; large-scale content-centric data sharing; large-scale content-centric databases; multilevel security; over-privileged users; performance improvement; privilege misuse detection; role-based access control; short-text snippets; textual content matching; Authorization; Awards activities; Data models; Databases; Semantics; Content-based Access Control; Database Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Big Data (Big Data), 2014 IEEE International Conference on
Conference_Location :
Washington, DC
Type :
conf
DOI :
10.1109/BigData.2014.7004294
Filename :
7004294
Link To Document :
بازگشت