Evaluating the effects of access control policies within NoSQL systems. Colombo, P. & Ferrari, E. Future Gener. Comput. Syst., 114:491–505, 2021. Paper doi abstract bibtex Access control is a key service of any data management system. It allows regulating the access to data resources at different granularity levels on the basis of access control models which vary on the protection options they offer. The more powerful is the access control model in terms of protection requirements, the more difficult is for security administrators to understand the effect of a set of access control policies on the protected resources. This is further complicated within schemaless systems, like NoSQL datastores, when fine grained access control policies are specified for data resources characterized by heterogeneous structures. The lack of a reference data model and related manipulation languages exacerbates this issue. To the best of our knowledge, a general approach to evaluate the impact of access control policies on the protected resources within NoSQL systems is still missing. In this paper, we start to fill this void, by proposing a data model agnostic approach, which, starting from schemaless datasets protected by different discretionary access control models, derives a view of the protected resources that points out authorized and unauthorized contents. Experimental results show the approach efficiency even with large datasets.
@article{DBLP:journals/fgcs/ColomboF21,
title = {Evaluating the effects of access control policies within NoSQL systems},
author = {Pietro Colombo and Elena Ferrari},
url = {https://doi.org/10.1016/j.future.2020.08.026},
doi = {10.1016/j.future.2020.08.026},
year = {2021},
date = {2021-01-01},
journal = {Future Gener. Comput. Syst.},
volume = {114},
pages = {491--505},
abstract = {Access control is a key service of any data management system. It allows regulating the access to data resources at different granularity levels on the basis of access control models which vary on the protection options they offer. The more powerful is the access control model in terms of protection requirements, the more difficult is for security administrators to understand the effect of a set of access control policies on the protected resources. This is further complicated within schemaless systems, like NoSQL datastores, when fine grained access control policies are specified for data resources characterized by heterogeneous structures. The lack of a reference data model and related manipulation languages exacerbates this issue. To the best of our knowledge, a general approach to evaluate the impact of access control policies on the protected resources within NoSQL systems is still missing. In this paper, we start to fill this void, by proposing a data model agnostic approach, which, starting from schemaless datasets protected by different discretionary access control models, derives a view of the protected resources that points out authorized and unauthorized contents. Experimental results show the approach efficiency even with large datasets.},
keywords = {Access control; NoSQL datastores; Big data; Authorized views},
pubstate = {published},
tppubtype = {article}
}
Downloads: 0
{"_id":"2efcqZxWpm3bD57YC","bibbaseid":"colombo-ferrari-evaluatingtheeffectsofaccesscontrolpolicieswithinnosqlsystems-2021","author_short":["Colombo, P.","Ferrari, E."],"bibdata":{"bibtype":"article","type":"article","title":"Evaluating the effects of access control policies within NoSQL systems","author":[{"firstnames":["Pietro"],"propositions":[],"lastnames":["Colombo"],"suffixes":[]},{"firstnames":["Elena"],"propositions":[],"lastnames":["Ferrari"],"suffixes":[]}],"url":"https://doi.org/10.1016/j.future.2020.08.026","doi":"10.1016/j.future.2020.08.026","year":"2021","date":"2021-01-01","journal":"Future Gener. Comput. Syst.","volume":"114","pages":"491–505","abstract":"Access control is a key service of any data management system. It allows regulating the access to data resources at different granularity levels on the basis of access control models which vary on the protection options they offer. The more powerful is the access control model in terms of protection requirements, the more difficult is for security administrators to understand the effect of a set of access control policies on the protected resources. This is further complicated within schemaless systems, like NoSQL datastores, when fine grained access control policies are specified for data resources characterized by heterogeneous structures. The lack of a reference data model and related manipulation languages exacerbates this issue. To the best of our knowledge, a general approach to evaluate the impact of access control policies on the protected resources within NoSQL systems is still missing. In this paper, we start to fill this void, by proposing a data model agnostic approach, which, starting from schemaless datasets protected by different discretionary access control models, derives a view of the protected resources that points out authorized and unauthorized contents. Experimental results show the approach efficiency even with large datasets.","keywords":"Access control; NoSQL datastores; Big data; Authorized views","pubstate":"published","tppubtype":"article","bibtex":"@article{DBLP:journals/fgcs/ColomboF21,\r\ntitle = {Evaluating the effects of access control policies within NoSQL systems},\r\nauthor = {Pietro Colombo and Elena Ferrari},\r\nurl = {https://doi.org/10.1016/j.future.2020.08.026},\r\ndoi = {10.1016/j.future.2020.08.026},\r\nyear = {2021},\r\ndate = {2021-01-01},\r\njournal = {Future Gener. Comput. Syst.},\r\nvolume = {114},\r\npages = {491--505},\r\nabstract = {Access control is a key service of any data management system. It allows regulating the access to data resources at different granularity levels on the basis of access control models which vary on the protection options they offer. The more powerful is the access control model in terms of protection requirements, the more difficult is for security administrators to understand the effect of a set of access control policies on the protected resources. This is further complicated within schemaless systems, like NoSQL datastores, when fine grained access control policies are specified for data resources characterized by heterogeneous structures. The lack of a reference data model and related manipulation languages exacerbates this issue. To the best of our knowledge, a general approach to evaluate the impact of access control policies on the protected resources within NoSQL systems is still missing. In this paper, we start to fill this void, by proposing a data model agnostic approach, which, starting from schemaless datasets protected by different discretionary access control models, derives a view of the protected resources that points out authorized and unauthorized contents. Experimental results show the approach efficiency even with large datasets.},\r\nkeywords = {Access control; NoSQL datastores; Big data; Authorized views},\r\npubstate = {published},\r\ntppubtype = {article}\r\n}\r\n","author_short":["Colombo, P.","Ferrari, E."],"key":"DBLP:journals/fgcs/ColomboF21","id":"DBLP:journals/fgcs/ColomboF21","bibbaseid":"colombo-ferrari-evaluatingtheeffectsofaccesscontrolpolicieswithinnosqlsystems-2021","role":"author","urls":{"Paper":"https://doi.org/10.1016/j.future.2020.08.026"},"keyword":["Access control; NoSQL datastores; Big data; Authorized views"],"metadata":{"authorlinks":{}}},"bibtype":"article","biburl":"http://strict.dista.uninsubria.it/wp-content/uploads/2021/10/strict.bib","dataSources":["gCSZRFeq7GvXmEPsn"],"keywords":["access control; nosql datastores; big data; authorized views"],"search_terms":["evaluating","effects","access","control","policies","within","nosql","systems","colombo","ferrari"],"title":"Evaluating the effects of access control policies within NoSQL systems","year":2021}