8
Alberto Belussi, Barbara Catania, Eliseo Clementini, and Elena Ferrari
Examples and discussions concerning how such functions can be applied to mediation systems and consistency checking are also provided.
1.3 Spatial Data Protection
Recent developments in information system technologies have resulted in computerizing many applications in various business areas. Data have become a critical
asset in many organizations, and, therefore, protecting data has become an urgent
need. Data and information have to be protected from unauthorized access as well
as from malicious corruption. The advent of the Internet has made the access to data
and information much easier [6]. For example, users can now access large quantities
of information in a short space of time. This has further exacerbated the need for
protection.
Over the past three decades, various developments have been made on securing
data, most of them in the field of Database Management Systems [3]. Much of the
early work was on statistical database security. Then, in the 1970s, as research in
relational databases began, attention was directed toward access control issues. In
particular, work on discretionary access control models began. While some work on
mandatory security started in the late 1970s, it was not until the air force summer
study in 1982 that many of the efforts in multilevel secure database management
systems were initiated. This resulted in the development of various secure database
system prototypes and products [3]. In the 1990s, with the advent of new technologies such as digital libraries, the Web, and collaborative computing systems, there
was much interest in security not only from government organizations but also from
commerce and industry. Database systems are no longer stand-alone systems. They
are being integrated into various applications such as multimedia, electronic commerce, mobile computing systems, digital libraries, and collaboration systems, and
therefore more complex security mechanisms should be developed [6].
Traditionally [3], securing data requires dealing with three main issues: authenticity, confidentiality, and integrity. Satisfying data authenticity means that the subject receiving data is guaranteed that they actually come from the expected source.
Related to this issue is that of ownership protection, that is, ensuring that the protected data cannot be misused and maliciously transferred to unauthorized users.
Ensuring data confidentiality means that data contents can be disclosed only to authorized users. By contrast, the term integrity implies two different security properties. The first refers to data protection from unauthorized modification operations,
whereas the second means that data contents are not altered during their transmission over the net. In past decades, several security mechanisms have been proposed to ensure such security properties in different environments and application
domains. Usually, such solutions enforce integrity through access control mechanisms and encryption-based techniques, and confidentiality through access control
mechanisms, whereas data authenticity requires the use of watermarking and digital
signature techniques.
However, these traditional security mechanisms are not always adequate to
meet the requirements of new data and emerging applications, which call for more
Précédent

- 310/317

Suivant