Blockaid: Data Access Policy Enforcement for Web Applications
Wen Zhang, Eric Sheng, Michael Alan Chang, Aurojit Panda, Mooly Sagiv, Scott Shenker
Abstract
Modern web applications serve large amounts of sensitive user data, access to which is typically governed by data-access policies. Enforcing such policies is crucial to preventing improper data access, and prior work has proposed many enforcement mechanisms. However, these prior methods either alter application semantics or require adopting a new programming model; the former can result in unexpected application behavior, while the latter cannot be used with existing web frameworks. Blockaid is an access-policy enforcement system that preserves application semantics and is compatible with existing web frameworks. It intercepts database queries from the application, attempts to verify that each query is policy-compliant, and blocks queries that are not. It verifies policy compliance using SMT solvers and generalizes and caches previous compliance decisions for better performance. We show that Blockaid supports existing web applications while requiring minimal code changes and adding only modest overheads. * Work done while at UC Berkeley.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 07e7729a-ccd7-4b85-a312-033b7aca98f3Cited by top-tier papers6
- Halfmoon: Log-Optimal Fault-Tolerant Stateful Serverless ComputingSheng Qi, Xuanzhe Liu, Xin JinSOSP 2023 · 16 citations
- Paralegal: Practical Static Analysis for Privacy BugsJustus Adam, Carolyn Zech, Livia Zhu, Sreshtaa Rajesh et al.OSDI 2025 · 2 citations
- Edna: Disguising and Revealing User Data in Web ApplicationsLillian Tsai, Hannah Gross, Eddie Kohler, M. Frans Kaashoek et al.SOSP 2023 · 1 citation
- Mitigating Injection Attacks against E2EE Applications via View-Based PartitioningAndrés Fábrega, Samuel Breckenridge, Armin Namavari, Thomas RistenpartUSENIX Security 2025
- PICACHV: Formally Verified Data Use Policy Enforcement for Secure Data AnalyticsHaobin Hiroki Chen, Hongbo Chen, Mingshen Sun, Chenghong Wang et al.USENIX Security 2025
Builds on2
Related papers
- Block public access: trust safety verification of access control policiesMalik Bouchet, Byron Cook, Bryant Cutler, Anna Druzkina et al.FSE 2020 · 25 citations
- Sesame: Practical End-to-End Privacy Compliance with Policy Containers and Privacy RegionsKinan Dak Albab, Artem Agvanian, Allen Aby, Corinn Tiffany et al.SOSP 2024 · 2 citations
- Extracting Database Access-Control Policies from Web ApplicationsWen Zhang, Dev Bali, Jamison Kerney, Aurojit Panda et al.OSDI 2026
- Verena: End-to-End Integrity Protection for Web ApplicationsNikolaos Karapanos, Alexandros Filios, Raluca Ada Popa, Srdjan CapkunS&P 2016 · 59 citations
- RuleKeeper: GDPR-Aware Personal Data Compliance for Web FrameworksMafalda Ferreira, Tiago Brito, José Fragoso Santos, Nuno SantosS&P 2023
