|
ABSTRACT
The security problem of statistical databases containing anonymous but individual records which may be evaluated by queries about sums and averages is considered. A model, more realistic than the previous ones, is proposed, in which nonexisting records for some keys can be allowed. Under the assumption that the system protects the individual's information by the well-known technique which avoids publishing summaries with small counts, several properties about the system and a necessary and sufficient condition for compromising the database have been derived. The minimum number of queries needed to compromise the database is also discussed.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
DEMILLO, R., DOBKIN, D., AND LI~TON, R. Even data bases that lie can be compromised. Res. Rep. #67, Dept. of Comptr. Sci., Yale U., New Haven, Conn., May 1976.
|
| |
2
|
DOBKIN, I)., JONES, A.K., AND LIPTON, R. Security data bases: Protection against user inference. Res. Rep. #65, Dept. of Comptr. Sci., Yale U., New Haven, Conn., April 1976.
|
 |
3
|
|
| |
4
|
FELLEGI, I.P. On the question of statistical confidentiality. J. Amer. Statist. Assoc. 67, 337 (March 1972), 7-18.
|
| |
5
|
FELLEaI, I.P., AND PHILLIPS, J.L, Statistical confidentiality: Some theory and applications to data dissemination. Ann. Econ. and Soc. Measurement, 8/2, 1974, pp. 399-409.
|
| |
6
|
HANSEN, M.H. Insuring confidentiality of individual records in data storage and retrieval for statistical purpose. Proc. AFIPS 1971 FJCC, Vol. 39, AFIPS Press, Montvale, N.J., pp. 579-585.
|
| |
7
|
H~q, M. Insuring individual's privacy from statistical data base users. Proc. A.~IPS 1975 NCC, Vol. 44, AFIPS Press, Montvale, N.J., pp. 941-946.
|
| |
8
|
H~RY, F. Graph Theory. Addison-Wesley, Reading, Mass., 1969.
|
| |
9
|
t-IOFFMAN, L.J., AND MILLER, W.F. Getting a personal dossier from a statistical data bank. Datamation 22, 5 (May 1976), 74-75.
|
 |
10
|
|
| |
11
|
LENNOX, M., AND YANDER ~OOT, T.J. Introduction to the Canadian socio-economic information management system. Canadian Statist. Rev. (Dominion Bur. of Statist., Ottawa) ~44, 3 (1969), v-xi.
|
| |
12
|
SCHLORER, J. identification and retrieval of personal records from a statistical data bank. Methods Inform. in Medicine 14, 1 (1975), 7-13.
|
| |
13
|
SCHLCiRER, J. Confidentiality of statistical records: A threat monitoring scheme for online dialogue. Methods Inform. in Medicine I5, 1 (1976), 36-42.
|
| |
14
|
SCHWARTZ, M.D., DENNING, D.E., AND DENNING, P.J. Theory of linear queries in data bases. CSD-TR 216, Purdue U., W. Lafayette, Ind., Nov. 1976.
|
 |
15
|
|
CITED BY 25
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Jon Kleinberg , Christos Papadimitriou , Prabhakar Raghavan, Auditing Boolean attributes, Proceedings of the nineteenth ACM SIGMOD-SIGACT-SIGART symposium on Principles of database systems, p.86-91, May 15-18, 2000, Dallas, Texas, United States
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Vangalur S. Alagar , Bernard Blanchard , David Glaser, Effective inference control mechanisms for securing statistical databases, Proceedings of the May 4-7, 1981, national computer conference, May 04-07, 1981, Chicago, Illinois
|
|