• DocumentCode
    44963
  • Title

    Accuracy-Constrained Privacy-Preserving Access Control Mechanism for Relational Data

  • Author

    Pervaiz, Zahid ; Aref, Walid G. ; Ghafoor, Abdul ; Prabhu, Nagabhushana

  • Author_Institution
    Sch. of Electr. & Comput. Eng., Center for Educ. & Res. in Inf. Assurance & Security (CERIAS), Purdue Univ., West Lafayette, IN, USA
  • Volume
    26
  • Issue
    4
  • fYear
    2014
  • fDate
    Apr-14
  • Firstpage
    795
  • Lastpage
    807
  • Abstract
    Access control mechanisms protect sensitive information from unauthorized users. However, when sensitive information is shared and a Privacy Protection Mechanism (PPM) is not in place, an authorized user can still compromise the privacy of a person leading to identity disclosure. A PPM can use suppression and generalization of relational data to anonymize and satisfy privacy requirements, e.g., k-anonymity and l-diversity, against identity and attribute disclosure. However, privacy is achieved at the cost of precision of authorized information. In this paper, we propose an accuracy-constrained privacy-preserving access control framework. The access control policies define selection predicates available to roles while the privacy requirement is to satisfy the k-anonymity or l-diversity. An additional constraint that needs to be satisfied by the PPM is the imprecision bound for each selection predicate. The techniques for workload-aware anonymization for selection predicates have been discussed in the literature. However, to the best of our knowledge, the problem of satisfying the accuracy constraints for multiple roles has not been studied before. In our formulation of the aforementioned problem, we propose heuristics for anonymization algorithms and show empirically that the proposed approach satisfies imprecision bounds for more permissions and has lower total imprecision than the current state of the art.
  • Keywords
    authorisation; data protection; query processing; relational databases; PPM; access control policies; accuracy constraints; accuracy-constrained privacy-preserving access control mechanism; anonymization algorithms; attribute disclosure; authorized information precision; authorized user; empirical analysis; identity disclosure; imprecision bound; imprecision bounds; k-anonymity; l-diversity; person privacy; privacy protection mechanism; privacy requirement anonymization; privacy requirement satisfaction; query processing; relational data generalization; relational data suppression; selection predicates; sensitive information protection; sensitive information sharing; unauthorized users; workload-aware anonymization; Access control; Data privacy; Partitioning algorithms; Privacy; Query processing; Semantics; $k$-anonymity; Access control; privacy; query evaluation;
  • fLanguage
    English
  • Journal_Title
    Knowledge and Data Engineering, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1041-4347
  • Type

    jour

  • DOI
    10.1109/TKDE.2013.71
  • Filename
    6512493