Decentralized information flow control for databases
نویسنده
چکیده
Privacy and integrity concerns have been mounting in recent years as sensitive data such asmedical records, social network records, and corporate and government secrets are increasingly being stored in online systems. The rate of high-profile breaches has illustrated that current techniques are inadequate for protecting sensitive information. Many of these breaches involve databases that handle information for a multitude of individuals, but databases don’t provide practical tools to protect those individuals from each other, so that task is relegated to the application.This dissertation describes a system that improves security in a principled way by extending the database system and the application platform to support information flow control. Information flow control has been gaining traction as a practical way to protect information in the contexts of programming languages and operating systems. Recent research advocates the decentralizedmodel for information flow control (difc), since it provides the necessary expressiveness to protect data for many individuals with varied security concerns.However, despite the fact thatmost applications implicated in breaches rely on relational databases, there havebeennoprior comprehensive attempts to extend difc to a database system. This dissertation introduces ifdb, which is a database management system that supports difc with minimal overhead. ifdb pioneers the Query by Label model, which provides applications with a simple way to delineate constraints on the confidentiality and integrity of the data they obtain from the database.This dissertation also defines new abstractions formanaging information flows in a database and proposes new ways to address covert channels. Finally, the ifdb implementation and case studies with real applications demonstrate that database support for difc improves security, is easy for developers to use, and has good performance. Thesis Supervisor: Barbara Liskov Title: Institute Professor
منابع مشابه
Adaptive Observer-Based Decentralized Scheme for Robust Nonlinear Power Flow Control Using HPFC
This paper investigates the robust decentralized nonlinear control of power flow in a power system using a new configuration of UPFC. This structure comprises two shunt converters and one series capacitor called as hybrid power flow controller (HPFC). A controller is designed via control Lyapunov function (CLF) and adaptive observer to surmount the problems of stability such as tracking desired...
متن کاملThe Real DFM Radius and Minimum Norm Plant Perturbation for General Control Information Flow Constraints
Abstract: The real decentralized fixed mode radius measures how “near” a decentralized LTI system is from having a decentralized fixed mode (DFM) present. In this paper, some properties of the real DFM radius are discussed, a procedure for computing the actual system parametric perturbations that achieve the real DFM radius is presented, and the real DFM radius is extended to deal with structur...
متن کاملThird-order Decentralized Safe Consensus Protocol for Inter-connected Heterogeneous Vehicular Platoons
In this paper, the stability analysis and control design of heterogeneous traffic flow is considered. It is assumed that the traffic flow consists of infinite number of cooperative non-identical vehicular platoons. Two different networks are investigated in stability analysis of heterogeneous traffic flow: 1) inter-platoon network which deals with the communication topology of lead vehicles and...
متن کاملDistributed multi-agent Load Frequency Control for a Large-scale Power System Optimized by Grey Wolf Optimizer
This paper aims to design an optimal distributed multi-agent controller for load frequency control and optimal power flow purposes. The controller parameters are optimized using Grey Wolf Optimization (GWO) algorithm. The designed optimal distributed controller is employed for load frequency control in the IEEE 30-bus test system with six generators. The controller of each generator is consider...
متن کاملKnown unknowns, unknown unknowns and information flow: new concepts in decentralized control
We introduce and analyze a model for decentralized control. The model is broad enough to include problems such as formation control, decentralization of the power grid and flocking. The objective of this paper is twofold. First, we show how the issue of decentralization goes beyond having agents know only part of the state of the system. In fact, we argue that a complete theory of decentralizat...
متن کامل