A constraint-based query modification engine for retrofitting COTS DBMS's
Moses Garuba, Ronald Langrin, Legand Burge · 2004
Models have been proposed to ensure the secrecy of data using various strategies. A number of these models however do not adequately address the problem of inference. This paper describes the design and implementation of a prototype that uses query modification along with security constraints to accurately return the proper information to the user whilst preventing unauthorized disclosure of data. The strategy works by augmenting a user's query with security constraints to ensure that the modified query is correct and safe in relation to the user's clearance level. The prototype is an implementation and extension of the query modification technique proposed by Keefe.