Advanced issues in data security and process compatibility
ABSTRACT
Defining access control to data sets is an important issue for data security. In this setting, inference problems make the task of specifying security policies in advance difficult since one has to anticipate all possible combinations of data pieces that can lead to disclose information that should be protected. In this presentation, we will show (1) how one can (semi-)automatically derive security policies to avoid inference problems in data management systems and (2) how to check process compatibility in the framework of SOA based on data handling. For the first case, our approach lies in the use of data dependencies. For the second case, we will resort to a cumulative approach.