Don't reveal my intension: Protecting user privacy using declarative preferences during distributed query processing

Nicholas L. Farnan*, Adam J. Lee, Panos K. Chrysanthis, Ting Yu

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

13 Citations (Scopus)

Abstract

In a centralized setting, the declarative nature of SQL is a major strength: a user can simply describe what she wants to retrieve, and need not worry about how the resulting query plan is actually generated and executed. However, in a decentralized setting, two query plans that produce the same result might actually reveal vastly different information about the intensional description of a user's query to the servers participating its evaluation. In cases where a user considers portions of her query to be sensitive, this is clearly problematic. In this paper, we address the specification and enforcement of querier privacy constraints on the execution of distributed database queries. We formalize a notion of intensional query privacy called (I,A)-privacy, and extend the syntax of SQL to allow users to enforce strict (I,A)-privacy constraints or partially ordered privacy/performance preferences over the execution of their queries.

Original languageEnglish
Title of host publicationComputer Security, ESORICS 2011 - 16th European Symposium on Research in Computer Security, Proceedings
PublisherSpringer Verlag
Pages628-647
Number of pages20
ISBN (Print)9783642238215
DOIs
Publication statusPublished - 2011
Externally publishedYes
Event16th European Symposium on Research in Computer Security, ESORICS 2011 - Leuven, Belgium
Duration: 12 Sept 201114 Sept 2011

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume6879 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference16th European Symposium on Research in Computer Security, ESORICS 2011
Country/TerritoryBelgium
CityLeuven
Period12/09/1114/09/11

Fingerprint

Dive into the research topics of 'Don't reveal my intension: Protecting user privacy using declarative preferences during distributed query processing'. Together they form a unique fingerprint.

Cite this