Data Usage Control for Distributed Systems

نویسنده

  • Florian Kelbert
چکیده

Data usage control provides mechanisms for data owners to remain in control over how their data is used after it has been accessed. Corresponding technical solutions are thus applicable in many distinct areas such as the protection of business, military and government secrets, intellectual property, as well as private user data. However, most existing solutions focus on the enforcement of data usage control within single systems and disregard distributed aspects of data usage control, i.e. how the usage of data can be controlled once data has been shared across systems and organizations. In fact, many data usage policies can only be enforced on a global scale, as they refer to data as well as data usage events happening within several distributed systems, e.g. “at each point in time at most two clerks might have a local copy of this contract”, or “a contract must be approved by at least two clerks before it is sent to the customer”. While such policies can intuitively be enforced using a centralized infrastructure, major drawbacks are that such solutions constitute a single point of failure and that they are expected to cause heavy communication and performance overheads. In order to address these open challenges, this dissertation contributes by providing (i) a formal distributed data usage control system model, and (ii) the first fully decentralized infrastructure for the preventive enforcement of data usage policies. More precisely, the provided model allows to track the flow of usage controlled data both within and across systems, as well as to coordinate the decision process of multiple distributed and independent decision points. To this end, this dissertation introduces formal and technical means to (a) propagate data usage policies to all relevant decision points, (b) identify all decision points that are relevant to evaluate a given policy, and (c) identify situations in which no coordination between decision points is necessary without compromising policy enforcement. Proofs of correctness of the presented formal methods are provided. The evaluation shows that the additional overhead introduced for cross-system data flow tracking and policy propagation is negligible. Further, it reveals in which scenarios the developed decentralized enforcement infrastructure is superior to a centralized approach. A security evaluation discusses security relevant assumptions as well as shortcomings and limitations of the proposed solution.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Using Regression based Control Limits and Probability Mixture Models for Monitoring Customer Behavior

In order to achieve the maximum flexibility in adaptation to ever changing customer’s expectations in customer relationship management, appropriate measures of customer behavior should be continually monitored. To this end, control charts adjusted for buyer’s/visitor’s prior intention to repurchase or visit again are suitable means taking into account the heterogeneity across customers. In the ...

متن کامل

E2DR: Energy Efficient Data Replication in Data Grid

Abstract— Data grids are an important branch of gird computing which provide mechanisms for the management of large volumes of distributed data. Energy efficiency has recently emerged as a hot topic in large distributed systems. The development of computing systems is traditionally focused on performance improvements driven by the demand of client's applications in scientific and business domai...

متن کامل

Data protection in heterogeneous distributed systems: A smart meter example

Usage control is concerned with how data is used after access has been granted. Enforcement mechanisms have been implemented for distributed systems like web based social networks (WBSN) at various levels of abstraction. We extend data usage control to heterogeneous distributed systems by implementing a policy enforcement mechanism for a smart meter connected to a WBSN. The idea is to provide u...

متن کامل

Decentralized Distributed Data Usage Control

Data usage control provides mechanisms for data owners to remain in control over how their data is used after it has been shared. Many data usage policies can only be enforced on a global scale, as they refer to data usage events happening within multiple distributed systems: ‘not more than three employees may ever read this document’, or ‘no copy of this document may be modified after it has b...

متن کامل

Achieving Accountability with Distributed Data Usage Control Technology

Distributed data usage control technology enforces obligations on future data usage in a preventive or a detective manner. The goal of preventive enforcement is to make sure that a data usage policy is adhered to. The goal of detective, or optimistic, enforcement is to maintain a log of policy violations, which directly provides technical means for accountability. Depending on the underlying tr...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2016