USENIX Security2017Top-tier venue
Qapla: Policy compliance for database-backed systems
Aastha Mehta, Eslam Elnikety, Katura Harvey, Deepak Garg, Peter Druschel
Abstract
Many database-backed systems store confidential data that is accessed on behalf of users with different privileges. Policies governing access are often fine-grained, being specific to users, time, accessed columns and rows, values in the database (e.g., user roles), and operators used in queries (e.g., aggregators, group by, and join). Today, applications are often relied upon to issue policy compliant queries or filter the results of non-compliant queries, which is vulnerable to application errors. Qapla provides an alternate approach to policy enforcement that neither depends on application correctness, nor on specialized database support. In Qapla, policies are specific to rows and columns and may additionally refer to the querier's identity and time, are specified in SQL, and stored in the database itself. We prototype Qapla in a database adapter, and evaluate it by enforcing applicable policies in the HotCRP conference management system and a system for managing academic job applications.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a275d21a-9574-4044-9cda-330cad1a54b2Cited by top-tier papers14
- Zeph: Cryptographic Enforcement of End-to-End Data PrivacyLukas Burkhalter, Nicolas Küchler, Alexander Viand, Hossein Shafagh et al.OSDI 2021 · 35 citations
- STORM: Refinement Types for Secure Web ApplicationsNico Lehmann, Rose Kunkel, Jordan Brown, Jean Yang et al.OSDI 2021 · 21 citations
- Blockaid: Data Access Policy Enforcement for Web ApplicationsWen Zhang, Eric Sheng, Michael Alan Chang, Aurojit Panda et al.OSDI 2022 · 8 citations
- General Data Protection Runtime: Enforcing Transparent GDPR Compliance for Existing ApplicationsDavid Klein, Benny Rolle, Thomas Barber, Manuel Karl et al.CCS 2023 · 5 citations
- Secure and Policy-Compliant Query Processing on Heterogeneous Computational Storage ArchitecturesHarshavardhan Unnibhavi, David Cerdeira, Antonio Barbalace, Nuno Santos et al.SIGMOD 2022 · 5 citations
Builds on1
Related papers
- Thoth: Comprehensive Policy Compliance in Data Retrieval SystemsEslam Elnikety, Aastha Mehta, Anjo Vahldiek-Oberwagner, Deepak Garg et al.USENIX Security 2016 · 30 citations
- Sieve: A Middleware Approach to Scalable Access Control for Database Management SystemsPrimal Pappachan, Roberto Yus, Sharad Mehrotra, Johann-Christoph FreytagVLDB 2020
- Extracting Database Access-Control Policies from Web ApplicationsWen Zhang, Dev Bali, Jamison Kerney, Aurojit Panda et al.OSDI 2026
- Excalibur: A Virtual Machine for Adaptive Fine-grained JIT-Compiled Query Execution based on VOILATim Gubner, Peter BonczVLDB 2023 · 10 citations
- Ensuring Authorized Updates in Multi-user Database-Backed ApplicationsKevin Eykholt, Atul Prakash, Barzan MozafariUSENIX Security 2017 · 4 citations
