Even though the idea of partitioning provenance graphs for access control was previously proposed, employing segments of the provenance DAG for fine-grained access control to provenance data has not been thoroughly explored. Hence, we take segments of a provenance graph, based on the extended OPM, and defined use a variant of regular expressions, and utilize them in our fine-grained access control language. It can not only return partial graphs to answer access requests but also introduce segments as restrictions in order to screen targeted data.
@article{arxiv.1912.00442,
title = {PACLP: a fine-grained partition-based access control policy language for provenance},
author = {Xinyu Fan and Faen Zhang and Jianfei Song and Jingming Guo and Fujie Gao},
journal= {arXiv preprint arXiv:1912.00442},
year = {2020}
}