Skip to main content

Controlled Query Evaluation with Open Queries for a Decidable Relational Submodel

  • Conference paper
Book cover Foundations of Information and Knowledge Systems (FoIKS 2006)

Part of the book series: Lecture Notes in Computer Science ((LNISA,volume 3861))

Abstract

Controlled query evaluation for logic-oriented information systems provides a model for the dynamic enforcement of confidentiality policies even if users are able to reason about a priori knowledge and the answers to previous queries. Previous foundational work simply assumes that the control mechanism can solve the arising entailment problems (no matter how complex they may be), and deals only with closed queries. In this paper, we overcome these limitations by refining the abstract model for appropriately represented relational databases. We identify a relational submodel where all instances share a fixed infinite Herbrand domain but have finite base relations, and we require finite and domain-independent query results. Then, via suitable syntactic restrictions on the policy and query languages, each entailment problem occurring in the framework can be equivalently expressed as a universal validity problem within the Bernays-Schönfinkel class, whose (known) decidability in the classical setting is extended to our framework. For both refusal and lying, we design and verify evaluation methods for open queries, exploiting controlled query evaluation of appropriate sequences of closed queries, which include answer completeness tests.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. Abiteboul, S., Hull, R., Vianu, V.: Foundations of Databases. Addison-Wesley, Reading (1995)

    MATH  Google Scholar 

  2. Ackermann, W.: Solvable Cases of the Decision Problem. North-Holland, Amsterdam (1968)

    Google Scholar 

  3. Andreka, H., Nemeti, I., van Benthem, J.: Modal languages and bounded fragments of predicate logic. Journal of Philosophical Logic 27(3), 217–274 (1998)

    Article  MATH  MathSciNet  Google Scholar 

  4. Biskup, J.: For unknown secrecies refusal is better than lying. Data and Knowledge Engineering 33, 1–23 (2000)

    Article  MATH  Google Scholar 

  5. Biskup, J., Bonatti, P.A.: Lying versus refusal for known potential secrets. Data and Knowledge Engineering 38, 199–222 (2001)

    Article  MATH  Google Scholar 

  6. Biskup, J., Bonatti, P.A.: Controlled query evaluation for known policies by combining lying and refusal. Annals of Mathematics and Artificial Intelligence 40, 37–62 (2004)

    Article  MATH  MathSciNet  Google Scholar 

  7. Biskup, J., Bonatti, P.A.: Controlled query evaluation for enforcing confidentiality in complete information systems. Int. Journal of Information Security 3(1), 14–27 (2004)

    Article  MathSciNet  Google Scholar 

  8. Biskup, J., Weibert, T.: Refusal in incomplete databases. In: Research Directions in Data and Applications Security XVII, pp. 143–157. Kluwer, Boston (2004)

    Chapter  Google Scholar 

  9. Biskup, J., Weibert, T.: Keeping secrets in incomplete databases. In: Workshop on Foundations of Computer Security, LICS 2005, Chicago (2005), http://www.cs.chalmers.se/~andrei/FCS05/

  10. Bonatti, P.A., Kraus, S., Subrahmanian, V.S.: Foundations of secure deductive databases. IEEE Transactions on Knowledge and Data Engineering 7(3), 406–422 (1995)

    Article  Google Scholar 

  11. Brodsky, A., Farkas, C., Jajodia, S.: Secure databases: constraints, inference channels, and monitoring disclosures. IEEE Transactions on Knowledge and Data Engineering 12(6), 900–919 (2000)

    Article  Google Scholar 

  12. Brodsky, A., Farkas, C., Wijesekera, D., Wang, X.S.: Constraints, inference channels and secure databases. In: Dechter, R. (ed.) CP 2000. LNCS, vol. 1894, pp. 98–113. Springer, Heidelberg (2000)

    Chapter  Google Scholar 

  13. Cuppens, F., Gabillon, A.: Cover story management. Data and Knowledge Engineering 37, 177–201 (2001)

    Article  MATH  Google Scholar 

  14. Dawson, S., De Capitani di Vimercati, S., Lincoln, P., Samarati, P.: Minimal data upgrading to prevent inference and association attacks. In: Proc. of the 18th ACM SIGMOD-SIGACT-SIGART Symposium on Principles of Database Systems (PODS), pp. 114–125 (1999)

    Google Scholar 

  15. Dawson, S., De Capitani di Vimercati, S., Samarati, P.: Specification and enforcement of classification and inference constraints. In: IEEE Symposium on Security and Privacy 1999, pp. 181–195 (1999)

    Google Scholar 

  16. Ebbinghaus, H.-D., Flum, J.: Finite Model Theory. Springer, Berlin (1995)

    MATH  Google Scholar 

  17. Elmasri, R., Navathe, S.B.: Fundamentals of Database Systems, 3rd edn. Addison-Wesley, Reading (2000)

    Google Scholar 

  18. Farkas, C., Jajodia, S.: The inference problem: a survey. ACM SIGKDD Explorations Newsletter 4(2), 6–11 (2002)

    Article  Google Scholar 

  19. Graedel, E.: On the restraining power of guards. Journal of Symbolic Logic 64(4), 1719–1742 (1999)

    Article  MATH  MathSciNet  Google Scholar 

  20. Libkin, L.: Elements of Finite Model Theory. Springer, Berlin (2004)

    MATH  Google Scholar 

  21. Lloyd, J.W.: Foundations of Logic Programming. Springer, Heidelberg (1987)

    MATH  Google Scholar 

  22. Shoenfield, J.R.: Mathematical Logic. Addison-Wesley, Reading (1967)

    MATH  Google Scholar 

  23. Sicherman, G.L., de Jonge, W., van de Riet, R.P.: Answering queries without revealing secrets. ACM Transactions on Database Systems 8(1), 41–59 (1983)

    Article  MATH  Google Scholar 

  24. Su, T.A., Ozsoyoglu, G.: Controlling FD and MVD inferences in multilevel relational database systems. IEEE Trans. on Knowledge and Data Engineering 3(4), 474–485 (1991)

    Article  Google Scholar 

  25. Winslett, M., Smith, K., Qian, X.: Formal query languages for secure relational databases. ACM Transactions on Database Systems 19(4), 626–662 (1994)

    Article  Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2006 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Biskup, J., Bonatti, P. (2006). Controlled Query Evaluation with Open Queries for a Decidable Relational Submodel. In: Dix, J., Hegner, S.J. (eds) Foundations of Information and Knowledge Systems. FoIKS 2006. Lecture Notes in Computer Science, vol 3861. Springer, Berlin, Heidelberg. https://doi.org/10.1007/11663881_4

Download citation

  • DOI: https://doi.org/10.1007/11663881_4

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-540-31782-1

  • Online ISBN: 978-3-540-31784-5

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics