þÿ<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:dt="uuid:C2F41010-65B3-11d1-A29F-00AA00C14882" xmlns="http://www.w3.org/TR/REC-html40"> <head> <meta name=Title content="Scalable Access Control for Lineage Information"> <meta name=Keywords content=""> <meta http-equiv=Content-Type content="text/html; charset=unicode"> <meta name=ProgId content=Word.Document> <meta name=Generator content="Microsoft Word 10"> <meta name=Originator content="Microsoft Word 10"> <link rel=File-List href="index_files/filelist.xml"> <link rel=Edit-Time-Data href="index_files/editdata.mso"> <link rel=OLE-Object-Data href="index_files/oledata.mso"> <!--[if !mso]> <style> v\:* {behavior:url(#default#VML);} o\:* {behavior:url(#default#VML);} w\:* {behavior:url(#default#VML);} .shape {behavior:url(#default#VML);} </style> <![endif]--> <title>Scalable Access Control for Lineage Information</title> <!--[if gte mso 9]><xml> <o:DocumentProperties> <o:Author>Arnie Rosenthal</o:Author> <o:Template>Normal</o:Template> <o:LastAuthor>Jane-Ellen Long</o:LastAuthor> <o:Revision>2</o:Revision> <o:LastPrinted>2009-02-12T02:09:00Z</o:LastPrinted> <o:Created>2009-02-18T19:15:00Z</o:Created> <o:LastSaved>2009-02-18T19:15:00Z</o:LastSaved> <o:Pages>4</o:Pages> <o:Words>9188</o:Words> <o:Characters>52377</o:Characters> <o:Company>The MITRE Corporation</o:Company> <o:Lines>436</o:Lines> <o:Paragraphs>104</o:Paragraphs> <o:CharactersWithSpaces>64322</o:CharactersWithSpaces> <o:Version>10.265</o:Version> </o:DocumentProperties> <o:CustomDocumentProperties> <o:_NewReviewCycle dt:dt="string"></o:_NewReviewCycle> </o:CustomDocumentProperties> <o:OfficeDocumentSettings> <o:AllowPNG/> <o:DownloadComponents>96</o:DownloadComponents> <o:PixelsPerInch>1920x1200</o:PixelsPerInch> </o:OfficeDocumentSettings> </xml><![endif]--><!--[if gte mso 9]><xml> <w:WordDocument> <w:PrintFractionalCharacterWidth/> <w:HyphenationZone>0</w:HyphenationZone> <w:DoNotHyphenateCaps/> <w:DrawingGridHorizontalSpacing>5 pt</w:DrawingGridHorizontalSpacing> <w:DisplayHorizontalDrawingGridEvery>0</w:DisplayHorizontalDrawingGridEvery> <w:DisplayVerticalDrawingGridEvery>0</w:DisplayVerticalDrawingGridEvery> <w:DoNotShadeFormData/> <w:DocumentVariables> <w:EN.InstantFormat>&lt;ENInstantFormat&gt;&lt;Enabled&gt;1&lt;/Enabled&gt;&lt;ScanUnformatted&gt;0&lt;/ScanUnformatted&gt;&lt;ScanChanges&gt;1&lt;/ScanChanges&gt;&lt;/ENInstantFormat&gt;</w:EN.InstantFormat> <w:EN.Libraries>&lt;ENLibraries&gt;&lt;Libraries&gt;&lt;item&gt;BibliographicDB.enl&lt;/item&gt;&lt;/Libraries&gt;&lt;/ENLibraries&gt;</w:EN.Libraries> </w:DocumentVariables> </w:WordDocument> </xml><![endif]--> <style> <!-- /* Font Definitions */ @font-face {font-family:"Times New Roman"; panose-1:0 2 2 6 3 5 4 5 2 3; mso-font-charset:0; mso-generic-font-family:auto; mso-font-pitch:variable; mso-font-signature:50331648 0 0 0 1 0;} @font-face {font-family:Arial; panose-1:0 2 11 6 4 2 2 2 2 2; mso-font-charset:0; mso-generic-font-family:auto; mso-font-pitch:variable; mso-font-signature:50331648 0 0 0 1 0;} @font-face {font-family:"Courier New"; panose-1:0 2 7 3 9 2 2 5 2 4; mso-font-charset:0; mso-generic-font-family:auto; mso-font-pitch:variable; mso-font-signature:50331648 0 0 0 1 0;} @font-face {font-family:Geneva; panose-1:0 2 11 5 3 3 4 4 4 2; mso-font-charset:0; mso-generic-font-family:auto; mso-font-pitch:variable; mso-font-signature:50331648 0 0 0 1 0;} @font-face {font-family:Wingdings; panose-1:0 5 2 1 2 1 8 4 8 7; mso-font-charset:2; mso-generic-font-family:auto; mso-font-pitch:variable; mso-font-signature:0 16 0 0 -2147483648 0;} @font-face {font-family:Tahoma; panose-1:0 2 11 6 4 3 5 4 4 2; mso-font-charset:0; mso-generic-font-family:auto; mso-font-pitch:variable; mso-font-signature:50331648 0 0 0 1 0;} @font-face {font-family:"Cambria Math"; mso-font-alt:"Times New Roman"; mso-font-charset:0; mso-generic-font-family:roman; mso-font-pitch:variable; mso-font-signature:-1610611985 1107304683 0 0 159 0;} @font-face {font-family:Consolas; mso-font-charset:0; mso-generic-font-family:modern; mso-font-pitch:fixed; mso-font-signature:-1610611985 1073750091 0 0 159 0;} @font-face {font-family:Calibri; mso-font-charset:0; mso-generic-font-family:swiss; mso-font-pitch:variable; mso-font-signature:-1610611985 1073750139 0 0 159 0;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {mso-style-parent:""; margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} h1 {mso-style-parent:""; mso-style-next:"Normal \(Post-Header\)"; margin-top:12.0pt; margin-right:0pt; margin-bottom:12.0pt; margin-left:18.0pt; text-align:left; text-indent:-18.0pt; line-height:normal; mso-pagination:widow-orphan; page-break-after:avoid; mso-outline-level:1; mso-list:l33 level1 lfo68; font-size:12.0pt; font-family:"Times New Roman"; color:windowtext; mso-font-kerning:0pt; font-weight:bold;} h2 {mso-style-parent:"Heading 1"; mso-style-next:"Normal \(Post-Header\)"; margin-top:12.0pt; margin-right:0pt; margin-bottom:12.0pt; margin-left:36.0pt; text-align:left; text-indent:-23.75pt; line-height:normal; mso-pagination:widow-orphan; page-break-after:avoid; mso-outline-level:2; mso-list:l33 level2 lfo68; tab-stops:72.0pt; font-size:11.0pt; font-family:"Times New Roman"; color:windowtext; font-weight:bold;} h3 {mso-style-parent:"Heading 2"; mso-style-next:Normal; margin-top:12.0pt; margin-right:0pt; margin-bottom:0pt; margin-left:19.25pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; mso-outline-level:3; mso-list:l33 level3 lfo68; tab-stops:72.0pt; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext; font-weight:bold;} h4 {mso-style-next:Normal; margin-top:12.0pt; margin-right:0pt; margin-bottom:3.0pt; margin-left:0pt; text-align:justify; text-indent:0pt; line-height:normal; mso-pagination:widow-orphan; page-break-after:avoid; mso-outline-level:4; font-size:14.0pt; font-family:"Times New Roman"; color:windowtext; font-weight:bold;} h5 {mso-style-next:Normal; margin-top:12.0pt; margin-right:0pt; margin-bottom:3.0pt; margin-left:0pt; text-align:justify; text-indent:0pt; line-height:normal; mso-pagination:widow-orphan; mso-outline-level:5; font-size:13.0pt; font-family:"Times New Roman"; color:windowtext; font-weight:bold; font-style:italic;} h6 {mso-style-next:Normal; margin-top:12.0pt; margin-right:0pt; margin-bottom:3.0pt; margin-left:0pt; text-align:justify; text-indent:0pt; line-height:normal; mso-pagination:widow-orphan; mso-outline-level:6; font-size:11.0pt; font-family:"Times New Roman"; color:windowtext; font-weight:bold;} p.MsoHeading7, li.MsoHeading7, div.MsoHeading7 {mso-style-next:Normal; margin-top:12.0pt; margin-right:0pt; margin-bottom:3.0pt; margin-left:0pt; text-align:justify; text-indent:0pt; line-height:normal; mso-pagination:widow-orphan; mso-outline-level:7; font-size:12.0pt; font-family:"Times New Roman"; color:windowtext;} p.MsoHeading8, li.MsoHeading8, div.MsoHeading8 {mso-style-next:Normal; margin-top:12.0pt; margin-right:0pt; margin-bottom:3.0pt; margin-left:0pt; text-align:justify; text-indent:0pt; line-height:normal; mso-pagination:widow-orphan; mso-outline-level:8; font-size:12.0pt; font-family:"Times New Roman"; color:windowtext; font-style:italic;} p.MsoHeading9, li.MsoHeading9, div.MsoHeading9 {mso-style-next:Normal; margin-top:12.0pt; margin-right:0pt; margin-bottom:3.0pt; margin-left:0pt; text-align:justify; text-indent:0pt; line-height:normal; mso-pagination:widow-orphan; mso-outline-level:9; font-size:11.0pt; font-family:Arial; color:windowtext;} p.MsoIndex1, li.MsoIndex1, div.MsoIndex1 {mso-style-next:Normal; margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.MsoIndex2, li.MsoIndex2, div.MsoIndex2 {mso-style-next:Normal; margin-top:0pt; margin-right:0pt; margin-bottom:0pt; margin-left:18.0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.MsoToc1, li.MsoToc1, div.MsoToc1 {mso-style-next:Normal; margin-top:0pt; margin-right:0pt; margin-bottom:12.0pt; margin-left:0pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; tab-stops:90.0pt right 450.0pt; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.MsoToc2, li.MsoToc2, div.MsoToc2 {mso-style-parent:"TOC 1"; mso-style-next:Normal; margin-top:0pt; margin-right:0pt; margin-bottom:0pt; margin-left:18.0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; tab-stops:54.0pt right 450.0pt; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.MsoToc3, li.MsoToc3, div.MsoToc3 {mso-style-parent:"TOC 2"; mso-style-next:Normal; margin-top:0pt; margin-right:0pt; margin-bottom:0pt; margin-left:54.0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; tab-stops:90.0pt right 450.0pt; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.MsoToc4, li.MsoToc4, div.MsoToc4 {mso-style-parent:"TOC 3"; mso-style-next:Normal; margin-top:0pt; margin-right:0pt; margin-bottom:0pt; margin-left:90.0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; tab-stops:126.0pt right 450.0pt; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.MsoToc5, li.MsoToc5, div.MsoToc5 {mso-style-next:Normal; margin-top:0pt; margin-right:0pt; margin-bottom:12.0pt; margin-left:0pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; tab-stops:27.0pt right 450.0pt; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.MsoToc6, li.MsoToc6, div.MsoToc6 {mso-style-next:Normal; margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; tab-stops:27.0pt right 450.0pt; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.MsoToc7, li.MsoToc7, div.MsoToc7 {mso-style-parent:"TOC 5"; mso-style-next:Normal; margin-top:0pt; margin-right:0pt; margin-bottom:12.0pt; margin-left:0pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; tab-stops:27.0pt right 450.0pt; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.MsoToc8, li.MsoToc8, div.MsoToc8 {mso-style-parent:"TOC 6"; mso-style-next:Normal; margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; tab-stops:27.0pt right 450.0pt; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.MsoNormalIndent, li.MsoNormalIndent, div.MsoNormalIndent {margin-top:0pt; margin-right:0pt; margin-bottom:0pt; margin-left:36.0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.MsoFootnoteText, li.MsoFootnoteText, div.MsoFootnoteText {margin-top:0pt; margin-right:0pt; margin-bottom:0pt; margin-left:18.0pt; margin-bottom:.0001pt; text-align:justify; text-indent:-18.0pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.MsoCommentText, li.MsoCommentText, div.MsoCommentText {margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.MsoHeader, li.MsoHeader, div.MsoHeader {margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; tab-stops:center 216.0pt right 432.0pt; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.MsoFooter, li.MsoFooter, div.MsoFooter {margin:0pt; margin-bottom:.0001pt; text-align:center; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.MsoCaption, li.MsoCaption, div.MsoCaption {mso-style-next:Normal; margin:0pt; margin-bottom:.0001pt; text-align:center; text-indent:0pt; line-height:150%; mso-pagination:widow-orphan; font-size:10.0pt; font-family:Helvetica; color:windowtext; font-weight:bold;} span.MsoFootnoteReference {font-size:9.0pt; mso-text-raise:3.0pt;} span.MsoCommentReference {font-size:8.0pt;} span.MsoEndnoteReference {vertical-align:super;} p.MsoEndnoteText, li.MsoEndnoteText, div.MsoEndnoteText {margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.MsoTitle, li.MsoTitle, div.MsoTitle {margin-top:27.0pt; margin-right:0pt; margin-bottom:24.0pt; margin-left:0pt; text-align:center; text-indent:0pt; line-height:normal; mso-pagination:widow-orphan; font-size:14.0pt; font-family:"Times New Roman"; color:windowtext; font-weight:bold;} a:link, span.MsoHyperlink {color:blue; text-decoration:underline; text-underline:single;} a:visited, span.MsoHyperlinkFollowed {color:purple; text-decoration:underline; text-underline:single;} p.MsoPlainText, li.MsoPlainText, div.MsoPlainText {margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.5pt; font-family:Consolas; color:windowtext;} p.MsoAutoSig, li.MsoAutoSig, div.MsoAutoSig {margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p {margin-right:0pt; mso-margin-top-alt:auto; mso-margin-bottom-alt:auto; margin-left:0pt; text-align:justify; text-indent:12.25pt; line-height:12.0pt; mso-pagination:widow-orphan; font-size:10.0pt; font-family:Arial; color:black;} cite {} p.Quotation, li.Quotation, div.Quotation {mso-style-name:Quotation; margin-top:0pt; margin-right:0pt; margin-bottom:0pt; margin-left:18.0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.FigureTableTOC, li.FigureTableTOC, div.FigureTableTOC {mso-style-name:"Figure\/Table\/TOC"; mso-style-next:Normal; margin-top:0pt; margin-right:0pt; margin-bottom:12.0pt; margin-left:0pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; tab-stops:right 450.0pt; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext; text-transform:uppercase; font-weight:bold;} p.NumberedReference, li.NumberedReference, div.NumberedReference {mso-style-name:"Numbered Reference"; margin-top:0pt; margin-right:0pt; margin-bottom:0pt; margin-left:18.0pt; margin-bottom:.0001pt; text-align:justify; text-indent:-18.0pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.Glossary, li.Glossary, div.Glossary {mso-style-name:Glossary; margin-top:0pt; margin-right:0pt; margin-bottom:0pt; margin-left:54.0pt; margin-bottom:.0001pt; text-align:justify; text-indent:-54.0pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.DistributionList, li.DistributionList, div.DistributionList {mso-style-name:"Distribution List"; margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.SectionNoHeading, li.SectionNoHeading, div.SectionNoHeading {mso-style-name:"Section No Heading"; mso-style-next:Normal; margin-top:0pt; margin-right:1.45pt; margin-bottom:12.0pt; margin-left:0pt; text-align:center; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; page-break-after:avoid; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext; text-transform:uppercase; font-weight:bold;} p.NameDateRef, li.NameDateRef, div.NameDateRef {mso-style-name:"Name\/Date Ref"; margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.AppendixLevel1, li.AppendixLevel1, div.AppendixLevel1 {mso-style-name:"Appendix Level 1"; mso-style-next:Normal; margin-top:0pt; margin-right:0pt; margin-bottom:12.0pt; margin-left:0pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; page-break-after:avoid; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext; text-transform:uppercase; font-weight:bold;} p.ExecSumLevel1, li.ExecSumLevel1, div.ExecSumLevel1 {mso-style-name:"ExecSum Level 1"; mso-style-next:Normal; margin-top:0pt; margin-right:0pt; margin-bottom:12.0pt; margin-left:0pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; page-break-after:avoid; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext; text-transform:uppercase; font-weight:bold;} p.FrntMatterHeadings, li.FrntMatterHeadings, div.FrntMatterHeadings {mso-style-name:"Frnt Matter Headings"; mso-style-next:Normal; margin-top:0pt; margin-right:1.45pt; margin-bottom:24.0pt; margin-left:0pt; text-align:center; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext; text-transform:uppercase; font-weight:bold;} p.GlossaryLT, li.GlossaryLT, div.GlossaryLT {mso-style-name:"Glossary \(L T\)"; margin-top:0pt; margin-right:0pt; margin-bottom:0pt; margin-left:18.0pt; margin-bottom:.0001pt; text-align:justify; text-indent:-18.0pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.List-1stLevel, li.List-1stLevel, div.List-1stLevel {mso-style-name:"List - 1st Level"; margin-top:0pt; margin-right:0pt; margin-bottom:0pt; margin-left:45.0pt; margin-bottom:.0001pt; text-align:justify; text-indent:-27.0pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.List-2ndLevel, li.List-2ndLevel, div.List-2ndLevel {mso-style-name:"List - 2nd Level"; margin-top:0pt; margin-right:0pt; margin-bottom:0pt; margin-left:72.0pt; margin-bottom:.0001pt; text-align:justify; text-indent:-27.0pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.ExecSumLevel2, li.ExecSumLevel2, div.ExecSumLevel2 {mso-style-name:"ExecSum Level 2"; mso-style-next:Normal; margin-top:0pt; margin-right:0pt; margin-bottom:12.0pt; margin-left:0pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; page-break-after:avoid; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext; font-weight:bold;} p.ExecSumLevel3, li.ExecSumLevel3, div.ExecSumLevel3 {mso-style-name:"ExecSum Level 3"; mso-style-next:Normal; margin-top:0pt; margin-right:0pt; margin-bottom:12.0pt; margin-left:18.0pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; page-break-after:avoid; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext; font-weight:bold;} p.AppendixLevel2, li.AppendixLevel2, div.AppendixLevel2 {mso-style-name:"Appendix Level 2"; mso-style-next:Normal; margin-top:0pt; margin-right:0pt; margin-bottom:12.0pt; margin-left:0pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; page-break-after:avoid; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext; font-weight:bold;} p.AppendixLevel3, li.AppendixLevel3, div.AppendixLevel3 {mso-style-name:"Appendix Level 3"; mso-style-next:Normal; margin-top:0pt; margin-right:0pt; margin-bottom:12.0pt; margin-left:18.0pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; page-break-after:avoid; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext; font-weight:bold;} p.Version21, li.Version21, div.Version21 {mso-style-name:"Version 2\.1"; mso-style-parent:"Distribution List"; margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.BalloonText, li.BalloonText, div.BalloonText {mso-style-name:"Balloon Text"; margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:8.0pt; font-family:Tahoma; color:windowtext;} span.comment {mso-style-name:comment; font-size:12.0pt; color:teal; display:none;} span.BalloonTextChar {mso-style-name:"Balloon Text Char"; font-size:8.0pt;} p.ListParagraph, li.ListParagraph, div.ListParagraph {mso-style-name:"List Paragraph"; margin-top:0pt; margin-right:0pt; margin-bottom:0pt; margin-left:36.0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} span.PlainTextChar {mso-style-name:"Plain Text Char"; font-size:10.5pt;} span.CommentTextChar {mso-style-name:"Comment Text Char";} p.CommentSubject, li.CommentSubject, div.CommentSubject {mso-style-name:"Comment Subject"; mso-style-parent:"Comment Text"; mso-style-next:"Comment Text"; margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext; font-weight:bold;} span.CommentSubjectChar {mso-style-name:"Comment Subject Char"; mso-style-parent:"Comment Text Char"; font-weight:bold;} p.Revision, li.Revision, div.Revision {mso-style-name:Revision; mso-style-parent:""; margin:0pt; margin-bottom:.0001pt; text-align:left; text-indent:0pt; line-height:normal; mso-pagination:widow-orphan; font-size:12.0pt; font-family:Times; color:windowtext;} span.PlaceholderText {mso-style-name:"Placeholder Text"; color:gray;} span.EndnoteTextChar {mso-style-name:"Endnote Text Char";} span.TitleChar {mso-style-name:"Title Char"; font-size:14.0pt; font-weight:bold;} p.Authornames, li.Authornames, div.Authornames {mso-style-name:"Author names"; mso-style-next:"Author Affiliation"; margin:0pt; margin-bottom:.0001pt; text-align:center; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:12.0pt; font-family:"Times New Roman"; color:windowtext;} p.abstract, li.abstract, div.abstract {mso-style-name:abstract; mso-style-parent:"Author names"; margin-top:0pt; margin-right:0pt; margin-bottom:12.0pt; margin-left:0pt; text-align:center; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:12.0pt; font-family:"Times New Roman"; color:windowtext;} span.AuthornamesChar {mso-style-name:"Author names Char"; font-size:12.0pt;} span.FootnoteTextChar {mso-style-name:"Footnote Text Char"; font-size:12.0pt;} span.abstractChar {mso-style-name:"abstract Char"; mso-style-parent:"Author names Char"; font-size:12.0pt;} p.Example, li.Example, div.Example {mso-style-name:Example; mso-style-update:auto; mso-style-next:"Example Text"; margin-top:0pt; margin-right:0pt; margin-bottom:0pt; margin-left:36.0pt; margin-bottom:.0001pt; text-align:justify; text-indent:-18.0pt; line-height:normal; mso-pagination:widow-orphan; mso-list:l47 level1 lfo65; font-size:10.0pt; font-family:Helvetica; color:windowtext; font-weight:bold;} p.AbstractHeading, li.AbstractHeading, div.AbstractHeading {mso-style-name:"Abstract Heading"; mso-style-parent:"Heading 1"; mso-style-next:AbstractBody; margin-top:0pt; margin-right:0pt; margin-bottom:12.0pt; margin-left:0pt; text-align:left; text-indent:0pt; line-height:normal; mso-pagination:widow-orphan; page-break-after:avoid; mso-outline-level:1; font-size:12.0pt; font-family:"Times New Roman"; color:windowtext; font-weight:bold;} p.AbstractBody, li.AbstractBody, div.AbstractBody {mso-style-name:AbstractBody; margin-top:0pt; margin-right:0pt; margin-bottom:12.0pt; margin-left:0pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext; font-style:italic;} p.AuthorName, li.AuthorName, div.AuthorName {mso-style-name:"Author Name"; mso-style-next:"Author Affiliation"; margin:0pt; margin-bottom:.0001pt; text-align:center; text-indent:0pt; line-height:normal; mso-pagination:widow-orphan; font-size:12.0pt; font-family:"Times New Roman"; color:windowtext;} p.AuthorAffiliation, li.AuthorAffiliation, div.AuthorAffiliation {mso-style-name:"Author Affiliation"; mso-style-parent:"Author Name"; margin-top:0pt; margin-right:0pt; margin-bottom:24.0pt; margin-left:0pt; text-align:center; text-indent:0pt; line-height:normal; mso-pagination:widow-orphan; font-size:12.0pt; font-family:"Times New Roman"; color:windowtext; font-style:italic;} span.Callout {mso-style-name:Callout; font-size:9.0pt;} p.Defn, li.Defn, div.Defn {mso-style-name:Defn; mso-style-next:"Defn Text"; margin-top:0pt; margin-right:0pt; margin-bottom:0pt; margin-left:48.25pt; margin-bottom:.0001pt; text-align:justify; text-indent:-18.0pt; line-height:normal; mso-pagination:widow-orphan; mso-list:l43 level1 lfo63; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext; font-weight:bold; font-style:italic;} p.DefnText, li.DefnText, div.DefnText {mso-style-name:"Defn Text"; margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext; font-style:italic;} p.ExampleText, li.ExampleText, div.ExampleText {mso-style-name:"Example Text"; mso-style-parent:Example; mso-style-next:Normal; margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:0pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:Helvetica; color:windowtext; font-weight:bold;} p.Footnote, li.Footnote, div.Footnote {mso-style-name:Footnote; margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:8.0pt; font-family:"Times New Roman"; color:windowtext;} p.Formula, li.Formula, div.Formula {mso-style-name:Formula; mso-style-next:Normal; margin:0pt; margin-bottom:.0001pt; text-align:center; text-indent:0pt; line-height:normal; mso-pagination:widow-orphan; mso-list:l27 level1 lfo66; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.NormalPost-Header, li.NormalPost-Header, div.NormalPost-Header {mso-style-name:"Normal \(Post-Header\)"; mso-style-next:Normal; margin-top:0pt; margin-right:0pt; margin-bottom:6.0pt; margin-left:0pt; text-align:justify; text-indent:0pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.Pagenumber, li.Pagenumber, div.Pagenumber {mso-style-name:"Page number"; margin:0pt; margin-bottom:.0001pt; text-align:center; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:Times; color:windowtext;} p.Reference, li.Reference, div.Reference {mso-style-name:Reference; margin:0pt; margin-bottom:.0001pt; text-align:justify; text-indent:12.25pt; line-height:normal; mso-pagination:widow-orphan; font-size:9.0pt; font-family:"Times New Roman"; color:windowtext;} p.TableCell, li.TableCell, div.TableCell {mso-style-name:"Table Cell"; margin:0pt; margin-bottom:.0001pt; text-align:center; text-indent:0pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext;} p.TableHeading, li.TableHeading, div.TableHeading {mso-style-name:"Table Heading"; mso-style-parent:"Table Cell"; mso-style-next:"Table Cell"; margin:0pt; margin-bottom:.0001pt; text-align:center; text-indent:0pt; line-height:normal; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; color:windowtext; font-weight:bold;} span.addmd1 {mso-style-name:addmd1; font-size:10.0pt; color:#777777;} p.reference0, li.reference0, div.reference0 {mso-style-name:reference; margin-top:0pt; margin-right:0pt; margin-bottom:0pt; margin-left:11.35pt; margin-bottom:.0001pt; text-align:justify; text-indent:-11.35pt; line-height:normal; mso-pagination:widow-orphan; mso-layout-grid-align:none; punctuation-wrap:simple; text-autospace:none; font-size:9.0pt; font-family:Times; color:windowtext;} span.E-mailSignatureChar {mso-style-name:"E-mail Signature Char";} p.Default, li.Default, div.Default {mso-style-name:Default; mso-style-parent:""; margin:0pt; margin-bottom:.0001pt; text-align:left; text-indent:0pt; line-height:normal; mso-pagination:widow-orphan; mso-layout-grid-align:none; text-autospace:none; font-size:12.0pt; font-family:"Times New Roman"; color:black;} span.Heading3Char {mso-style-name:"Heading 3 Char"; font-weight:bold;} /* Page Definitions */ @page {mso-footnote-separator:url(":index_files:header.htm") fs; mso-footnote-continuation-separator:url(":index_files:header.htm") fcs; mso-endnote-separator:url(":index_files:header.htm") es; mso-endnote-continuation-separator:url(":index_files:header.htm") ecs;} @page Section1 {size:612.0pt 792.0pt; margin:72.0pt 72.0pt 72.0pt 72.0pt; mso-header-margin:36.0pt; mso-footer-margin:72.0pt; mso-title-page:yes; mso-footer:url(":index_files:header.htm") f1; mso-paper-source:0;} div.Section1 {page:Section1;} @page Section2 {size:612.0pt 792.0pt; margin:108.0pt 81.0pt 108.0pt 81.0pt; mso-header-margin:36.0pt; mso-footer-margin:72.0pt; mso-columns:2 even 18.0pt; mso-footer:url(":index_files:header.htm") f1; mso-paper-source:0;} div.Section2 {page:Section2;} @page Section3 {size:612.0pt 792.0pt; margin:108.0pt 81.0pt 108.0pt 81.0pt; mso-header-margin:36.0pt; mso-footer-margin:72.0pt; mso-columns:2 even 18.0pt; mso-footer:url(":index_files:header.htm") f1; mso-paper-source:0;} div.Section3 {page:Section3;} /* List Definitions */ @list l0 {mso-list-id:-132; mso-list-type:simple; mso-list-template-ids:-1956998174;} @list l0:level1 {mso-level-tab-stop:90.0pt; mso-level-number-position:left; margin-left:90.0pt; text-indent:-18.0pt;} @list l1 {mso-list-id:-131; mso-list-type:simple; mso-list-template-ids:934175208;} @list l1:level1 {mso-level-tab-stop:72.0pt; mso-level-number-position:left; margin-left:72.0pt; text-indent:-18.0pt;} @list l2 {mso-list-id:-130; mso-list-type:simple; mso-list-template-ids:-1178331950;} @list l2:level1 {mso-level-tab-stop:54.0pt; mso-level-number-position:left; margin-left:54.0pt; text-indent:-18.0pt;} @list l3 {mso-list-id:-129; mso-list-type:simple; mso-list-template-ids:229128880;} @list l3:level1 {mso-level-tab-stop:36.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l4 {mso-list-id:-128; mso-list-type:simple; mso-list-template-ids:1378374566;} @list l4:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:90.0pt; mso-level-number-position:left; margin-left:90.0pt; text-indent:-18.0pt; font-family:Symbol;} @list l5 {mso-list-id:-127; mso-list-type:simple; mso-list-template-ids:-1599302516;} @list l5:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:72.0pt; mso-level-number-position:left; margin-left:72.0pt; text-indent:-18.0pt; font-family:Symbol;} @list l6 {mso-list-id:-126; mso-list-type:simple; mso-list-template-ids:-1625521338;} @list l6:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:54.0pt; mso-level-number-position:left; margin-left:54.0pt; text-indent:-18.0pt; font-family:Symbol;} @list l7 {mso-list-id:-125; mso-list-type:simple; mso-list-template-ids:-947909954;} @list l7:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:36.0pt; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l8 {mso-list-id:-120; mso-list-type:simple; mso-list-template-ids:1538396966;} @list l8:level1 {mso-level-tab-stop:18.0pt; mso-level-number-position:left; margin-left:18.0pt; text-indent:-18.0pt;} @list l9 {mso-list-id:-119; mso-list-type:simple; mso-list-template-ids:-715633966;} @list l9:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:18.0pt; mso-level-number-position:left; margin-left:18.0pt; text-indent:-18.0pt; font-family:Symbol;} @list l10 {mso-list-id:-5; mso-list-template-ids:-1693528044;} @list l10:level1 {mso-level-tab-stop:none; mso-level-number-position:left; mso-level-legacy:yes; mso-level-legacy-indent:0pt; mso-level-legacy-space:7.2pt; margin-left:0pt; text-indent:0pt;} @list l10:level2 {mso-level-text:"%1\.%2"; mso-level-tab-stop:none; mso-level-number-position:left; mso-level-legacy:yes; mso-level-legacy-indent:0pt; mso-level-legacy-space:7.2pt; margin-left:0pt; text-indent:0pt;} @list l10:level3 {mso-level-text:"%1\.%2\.%3"; mso-level-tab-stop:none; mso-level-number-position:left; mso-level-legacy:yes; mso-level-legacy-indent:0pt; mso-level-legacy-space:7.2pt; margin-left:0pt; text-indent:0pt;} @list l10:level4 {mso-level-text:"%1\.%2\.%3\.%4"; mso-level-tab-stop:none; mso-level-number-position:left; mso-level-legacy:yes; mso-level-legacy-indent:0pt; mso-level-legacy-space:7.2pt; margin-left:0pt; text-indent:0pt;} @list l10:level5 {mso-level-text:"%1\.%2\.%3\.%4\.%5"; mso-level-tab-stop:none; mso-level-number-position:left; mso-level-legacy:yes; mso-level-legacy-indent:0pt; mso-level-legacy-space:7.2pt; margin-left:0pt; text-indent:0pt;} @list l10:level6 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6"; mso-level-tab-stop:none; mso-level-number-position:left; mso-level-legacy:yes; mso-level-legacy-indent:0pt; mso-level-legacy-space:7.2pt; margin-left:0pt; text-indent:0pt;} @list l10:level7 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7"; mso-level-tab-stop:none; mso-level-number-position:left; mso-level-legacy:yes; mso-level-legacy-indent:0pt; mso-level-legacy-space:7.2pt; margin-left:0pt; text-indent:0pt;} @list l10:level8 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8"; mso-level-tab-stop:none; mso-level-number-position:left; mso-level-legacy:yes; mso-level-legacy-indent:0pt; mso-level-legacy-space:7.2pt; margin-left:0pt; text-indent:0pt;} @list l10:level9 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8\.%9"; mso-level-tab-stop:none; mso-level-number-position:left; mso-level-legacy:yes; mso-level-legacy-indent:0pt; mso-level-legacy-space:7.2pt; margin-left:0pt; text-indent:0pt;} @list l11 {mso-list-id:16085938; mso-list-type:hybrid; mso-list-template-ids:-1423779554 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l11:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:38.25pt; text-indent:-18.0pt; font-family:Symbol;} @list l12 {mso-list-id:83038381; mso-list-type:hybrid; mso-list-template-ids:1829015816 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l12:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:48.25pt; text-indent:-18.0pt; font-family:Symbol;} @list l12:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:84.25pt; text-indent:-18.0pt; font-family:"Courier New";} @list l12:level3 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:120.25pt; text-indent:-18.0pt; font-family:Wingdings;} @list l13 {mso-list-id:93670757; mso-list-type:hybrid; mso-list-template-ids:-627686958 390396534 1639433 1770505 984073 1639433 1770505 984073 1639433 1770505;} @list l13:level1 {mso-level-text:"Example %1\."; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt;} @list l14 {mso-list-id:98180528; mso-list-type:hybrid; mso-list-template-ids:1238298010 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l14:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l15 {mso-list-id:110781961; mso-list-type:hybrid; mso-list-template-ids:1957610678 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l15:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:49.5pt; text-indent:-18.0pt; font-family:Symbol;} @list l16 {mso-list-id:128088882; mso-list-template-ids:1189106676;} @list l16:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:18.0pt; text-indent:-18.0pt; font-family:Symbol;} @list l16:level2 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:39.6pt; text-indent:-21.6pt; font-family:Symbol;} @list l16:level3 {mso-level-text:"%1\.%2\.%3\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:61.2pt; text-indent:-25.2pt;} @list l16:level4 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:86.4pt; text-indent:-32.4pt; font-family:Symbol;} @list l16:level5 {mso-level-text:"%1\.%2\.%3\.%4\.%5\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:111.6pt; text-indent:-39.6pt;} @list l16:level6 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:136.8pt; text-indent:-46.8pt;} @list l16:level7 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:162.0pt; text-indent:-54.0pt;} @list l16:level8 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:187.2pt; text-indent:-61.2pt;} @list l16:level9 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8\.%9\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:216.0pt; text-indent:-72.0pt;} @list l17 {mso-list-id:146212769; mso-list-type:hybrid; mso-list-template-ids:-1044975470 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l17:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l17:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:"Courier New";} @list l18 {mso-list-id:166334659; mso-list-type:hybrid; mso-list-template-ids:2055747976 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l18:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l19 {mso-list-id:182015519; mso-list-template-ids:1599616660;} @list l19:level1 {mso-level-tab-stop:none; mso-level-number-position:left; margin-left:18.0pt; text-indent:-18.0pt;} @list l19:level2 {mso-level-text:"%1\.%2\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:39.6pt; text-indent:-21.6pt;} @list l19:level3 {mso-level-text:"%1\.%2\.%3\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:61.2pt; text-indent:-25.2pt;} @list l19:level4 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:86.4pt; text-indent:-32.4pt; font-family:Symbol;} @list l19:level5 {mso-level-text:"%1\.%2\.%3\.%4\.%5\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:111.6pt; text-indent:-39.6pt;} @list l19:level6 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:136.8pt; text-indent:-46.8pt;} @list l19:level7 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:162.0pt; text-indent:-54.0pt;} @list l19:level8 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:187.2pt; text-indent:-61.2pt;} @list l19:level9 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8\.%9\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:216.0pt; text-indent:-72.0pt;} @list l20 {mso-list-id:221524589; mso-list-type:hybrid; mso-list-template-ids:1448746798 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l20:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l21 {mso-list-id:223570023; mso-list-template-ids:1405657118;} @list l21:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:18.0pt; text-indent:-18.0pt; font-family:Symbol;} @list l21:level2 {mso-level-text:"%1\.%2\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:39.6pt; text-indent:-21.6pt;} @list l21:level3 {mso-level-text:"%1\.%2\.%3\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:61.2pt; text-indent:-25.2pt;} @list l21:level4 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:86.4pt; text-indent:-32.4pt; font-family:Symbol;} @list l21:level5 {mso-level-text:"%1\.%2\.%3\.%4\.%5\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:111.6pt; text-indent:-39.6pt;} @list l21:level6 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:136.8pt; text-indent:-46.8pt;} @list l21:level7 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:162.0pt; text-indent:-54.0pt;} @list l21:level8 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:187.2pt; text-indent:-61.2pt;} @list l21:level9 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8\.%9\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:216.0pt; text-indent:-72.0pt;} @list l22 {mso-list-id:267125310; mso-list-type:hybrid; mso-list-template-ids:1421537376 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l22:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:18.0pt; text-indent:-18.0pt; font-family:Symbol;} @list l23 {mso-list-id:282734691; mso-list-type:hybrid; mso-list-template-ids:-207030356 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l23:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l23:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:"Courier New";} @list l24 {mso-list-id:333727961; mso-list-type:hybrid; mso-list-template-ids:-621669678 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l24:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l24:level2 {mso-level-tab-stop:72.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l24:level3 {mso-level-tab-stop:108.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l24:level4 {mso-level-tab-stop:144.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l24:level5 {mso-level-tab-stop:180.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l24:level6 {mso-level-tab-stop:216.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l24:level7 {mso-level-tab-stop:252.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l24:level8 {mso-level-tab-stop:288.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l24:level9 {mso-level-tab-stop:324.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l25 {mso-list-id:341858375; mso-list-type:hybrid; mso-list-template-ids:-402502892 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l25:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l25:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:"Courier New";} @list l25:level3 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Wingdings;} @list l26 {mso-list-id:366680833; mso-list-type:hybrid; mso-list-template-ids:1473415102 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l26:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l27 {mso-list-id:397168614; mso-list-template-ids:1899648772;} @list l27:level1 {mso-level-style-link:Formula; mso-level-suffix:space; mso-level-text:"\(%1\)"; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:0pt; text-indent:0pt;} @list l27:level2 {mso-level-number-format:alpha-lower; mso-level-text:"%2\)"; mso-level-tab-stop:36.0pt; mso-level-number-position:left; margin-left:36.0pt; text-indent:-18.0pt;} @list l27:level3 {mso-level-number-format:roman-lower; mso-level-text:"%3\)"; mso-level-tab-stop:54.0pt; mso-level-number-position:left; margin-left:54.0pt; text-indent:-18.0pt;} @list l27:level4 {mso-level-text:"\(%4\)"; mso-level-tab-stop:72.0pt; mso-level-number-position:left; margin-left:72.0pt; text-indent:-18.0pt;} @list l27:level5 {mso-level-number-format:alpha-lower; mso-level-text:"\(%5\)"; mso-level-tab-stop:90.0pt; mso-level-number-position:left; margin-left:90.0pt; text-indent:-18.0pt;} @list l27:level6 {mso-level-number-format:roman-lower; mso-level-text:"\(%6\)"; mso-level-tab-stop:108.0pt; mso-level-number-position:left; margin-left:108.0pt; text-indent:-18.0pt;} @list l27:level7 {mso-level-tab-stop:126.0pt; mso-level-number-position:left; margin-left:126.0pt; text-indent:-18.0pt;} @list l27:level8 {mso-level-number-format:alpha-lower; mso-level-tab-stop:144.0pt; mso-level-number-position:left; margin-left:144.0pt; text-indent:-18.0pt;} @list l27:level9 {mso-level-number-format:roman-lower; mso-level-tab-stop:162.0pt; mso-level-number-position:left; margin-left:162.0pt; text-indent:-18.0pt;} @list l28 {mso-list-id:424036395; mso-list-type:hybrid; mso-list-template-ids:1803341980 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l28:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l28:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:"Courier New";} @list l29 {mso-list-id:447510918; mso-list-template-ids:-800440622;} @list l29:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:0pt; text-indent:0pt; font-family:Symbol;} @list l29:level2 {mso-level-text:"%1\.%2"; mso-level-tab-stop:none; mso-level-number-position:left; mso-level-legacy:yes; mso-level-legacy-indent:0pt; mso-level-legacy-space:7.2pt; margin-left:0pt; text-indent:0pt;} @list l29:level3 {mso-level-text:"%1\.%2\.%3"; mso-level-tab-stop:none; mso-level-number-position:left; mso-level-legacy:yes; mso-level-legacy-indent:0pt; mso-level-legacy-space:7.2pt; margin-left:0pt; text-indent:0pt;} @list l29:level4 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:0pt; text-indent:0pt; font-family:Symbol;} @list l29:level5 {mso-level-text:"%1\.%2\.%3\.%4\.%5"; mso-level-tab-stop:none; mso-level-number-position:left; mso-level-legacy:yes; mso-level-legacy-indent:0pt; mso-level-legacy-space:7.2pt; margin-left:0pt; text-indent:0pt;} @list l29:level6 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6"; mso-level-tab-stop:none; mso-level-number-position:left; mso-level-legacy:yes; mso-level-legacy-indent:0pt; mso-level-legacy-space:7.2pt; margin-left:0pt; text-indent:0pt;} @list l29:level7 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7"; mso-level-tab-stop:none; mso-level-number-position:left; mso-level-legacy:yes; mso-level-legacy-indent:0pt; mso-level-legacy-space:7.2pt; margin-left:0pt; text-indent:0pt;} @list l29:level8 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8"; mso-level-tab-stop:none; mso-level-number-position:left; mso-level-legacy:yes; mso-level-legacy-indent:0pt; mso-level-legacy-space:7.2pt; margin-left:0pt; text-indent:0pt;} @list l29:level9 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8\.%9"; mso-level-tab-stop:none; mso-level-number-position:left; mso-level-legacy:yes; mso-level-legacy-indent:0pt; mso-level-legacy-space:7.2pt; margin-left:0pt; text-indent:0pt;} @list l30 {mso-list-id:466747731; mso-list-type:hybrid; mso-list-template-ids:-847325204 1319158934 1639433 1770505 984073 1639433 1770505 984073 1639433 1770505;} @list l30:level1 {mso-level-number-format:alpha-upper; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:30.25pt; text-indent:-18.0pt;} @list l31 {mso-list-id:471561637; mso-list-type:hybrid; mso-list-template-ids:-74263848 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l31:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l31:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:"Courier New";} @list l32 {mso-list-id:541745013; mso-list-template-ids:1599616660;} @list l32:level1 {mso-level-tab-stop:none; mso-level-number-position:left; margin-left:18.0pt; text-indent:-18.0pt;} @list l32:level2 {mso-level-text:"%1\.%2\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:39.6pt; text-indent:-21.6pt;} @list l32:level3 {mso-level-text:"%1\.%2\.%3\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:61.2pt; text-indent:-25.2pt;} @list l32:level4 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:86.4pt; text-indent:-32.4pt; font-family:Symbol;} @list l32:level5 {mso-level-text:"%1\.%2\.%3\.%4\.%5\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:111.6pt; text-indent:-39.6pt;} @list l32:level6 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:136.8pt; text-indent:-46.8pt;} @list l32:level7 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:162.0pt; text-indent:-54.0pt;} @list l32:level8 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:187.2pt; text-indent:-61.2pt;} @list l32:level9 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8\.%9\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:216.0pt; text-indent:-72.0pt;} @list l33 {mso-list-id:575164636; mso-list-template-ids:1313997970;} @list l33:level1 {mso-level-style-link:"Heading 1"; mso-level-suffix:space; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:18.0pt; text-indent:-18.0pt;} @list l33:level2 {mso-level-style-link:"Heading 2"; mso-level-suffix:space; mso-level-text:"%1\.%2\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:36.0pt; text-indent:-23.75pt;} @list l33:level3 {mso-level-style-link:"Heading 3"; mso-level-suffix:space; mso-level-text:"%1\.%2\.%3\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:19.25pt; text-indent:12.25pt;} @list l33:level4 {mso-level-text:"%1\.%2\.%3\.%4\."; mso-level-tab-stop:90.0pt; mso-level-number-position:left; margin-left:86.4pt; text-indent:-32.4pt;} @list l33:level5 {mso-level-text:"%1\.%2\.%3\.%4\.%5\."; mso-level-tab-stop:126.0pt; mso-level-number-position:left; margin-left:111.6pt; text-indent:-39.6pt;} @list l33:level6 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\."; mso-level-tab-stop:144.0pt; mso-level-number-position:left; margin-left:136.8pt; text-indent:-46.8pt;} @list l33:level7 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\."; mso-level-tab-stop:180.0pt; mso-level-number-position:left; margin-left:162.0pt; text-indent:-54.0pt;} @list l33:level8 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8\."; mso-level-tab-stop:198.0pt; mso-level-number-position:left; margin-left:187.2pt; text-indent:-61.2pt;} @list l33:level9 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8\.%9\."; mso-level-tab-stop:234.0pt; mso-level-number-position:left; margin-left:216.0pt; text-indent:-72.0pt;} @list l34 {mso-list-id:579945426; mso-list-type:hybrid; mso-list-template-ids:165595898 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l34:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:39.0pt; text-indent:-18.0pt; font-family:Symbol;} @list l35 {mso-list-id:687021905; mso-list-type:hybrid; mso-list-template-ids:1230278814 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l35:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l36 {mso-list-id:724721102; mso-list-type:hybrid; mso-list-template-ids:-389408164 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l36:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l36:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:"Courier New";} @list l37 {mso-list-id:732847657; mso-list-type:hybrid; mso-list-template-ids:899336868 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l37:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l38 {mso-list-id:737047308; mso-list-type:hybrid; mso-list-template-ids:-1523926568 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l38:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:50.25pt; text-indent:-18.0pt; font-family:Symbol;} @list l39 {mso-list-id:746000769; mso-list-type:hybrid; mso-list-template-ids:1237219046 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l39:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:18.0pt; text-indent:-18.0pt; font-family:Symbol;} @list l40 {mso-list-id:765810776; mso-list-type:hybrid; mso-list-template-ids:-798589364 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l40:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:48.25pt; text-indent:-18.0pt; font-family:Symbol;} @list l40:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:84.25pt; text-indent:-18.0pt; font-family:"Courier New";} @list l40:level3 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:120.25pt; text-indent:-18.0pt; font-family:Wingdings;} @list l40:level4 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:156.25pt; text-indent:-18.0pt; font-family:Symbol;} @list l41 {mso-list-id:779296803; mso-list-type:hybrid; mso-list-template-ids:1144933820 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l41:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l42 {mso-list-id:785543179; mso-list-type:hybrid; mso-list-template-ids:1602543952 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l42:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l43 {mso-list-id:814831204; mso-list-type:hybrid; mso-list-template-ids:-549826092 -356763120 1639433 1770505 984073 1639433 1770505 984073 1639433 1770505;} @list l43:level1 {mso-level-style-link:Defn; mso-level-text:"Definition %1\."; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:48.25pt; text-indent:-18.0pt;} @list l44 {mso-list-id:889346172; mso-list-type:hybrid; mso-list-template-ids:-1543486492 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l44:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:38.65pt; text-indent:-18.0pt; font-family:Symbol;} @list l45 {mso-list-id:893078143; mso-list-type:hybrid; mso-list-template-ids:1137229222 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l45:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l45:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:"Courier New";} @list l45:level3 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Wingdings;} @list l46 {mso-list-id:927350178; mso-list-type:hybrid; mso-list-template-ids:1422691794 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l46:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l47 {mso-list-id:928391019; mso-list-type:hybrid; mso-list-template-ids:-1655959370 -575534140 1639433 1770505 984073 1639433 1770505 984073 1639433 1770505;} @list l47:level1 {mso-level-style-link:Example; mso-level-text:"Example %1\."; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt;} @list l48 {mso-list-id:990980615; mso-list-template-ids:-292892336;} @list l48:level1 {mso-level-start-at:3; mso-level-text:%1; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:18.0pt; text-indent:-18.0pt;} @list l48:level2 {mso-level-start-at:4; mso-level-text:"%1\.%2"; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:30.25pt; text-indent:-18.0pt;} @list l48:level3 {mso-level-text:"%1\.%2\.%3"; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:60.5pt; text-indent:-36.0pt;} @list l48:level4 {mso-level-text:"%1\.%2\.%3\.%4"; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:72.75pt; text-indent:-36.0pt;} @list l48:level5 {mso-level-text:"%1\.%2\.%3\.%4\.%5"; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:103.0pt; text-indent:-54.0pt;} @list l48:level6 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6"; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:115.25pt; text-indent:-54.0pt;} @list l48:level7 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7"; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:145.5pt; text-indent:-72.0pt;} @list l48:level8 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8"; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:157.75pt; text-indent:-72.0pt;} @list l48:level9 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8\.%9"; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:170.0pt; text-indent:-72.0pt;} @list l49 {mso-list-id:1006248226; mso-list-type:hybrid; mso-list-template-ids:-1392089882 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l49:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l50 {mso-list-id:1030689911; mso-list-type:hybrid; mso-list-template-ids:-1097452068 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l50:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l50:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:"Courier New";} @list l50:level3 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Wingdings;} @list l50:level4 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l50:level5 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:"Courier New";} @list l50:level6 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Wingdings;} @list l50:level7 {mso-level-tab-stop:252.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l50:level8 {mso-level-tab-stop:288.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l50:level9 {mso-level-tab-stop:324.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l51 {mso-list-id:1082142398; mso-list-type:hybrid; mso-list-template-ids:-1030866372 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l51:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:48.25pt; text-indent:-18.0pt; font-family:Symbol;} @list l52 {mso-list-id:1107043517; mso-list-type:hybrid; mso-list-template-ids:2099137640 -613661158 1639433 1770505 984073 1639433 1770505 984073 1639433 1770505;} @list l52:level1 {mso-level-text:%1; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt;} @list l52:level2 {mso-level-number-format:alpha-lower; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt;} @list l52:level3 {mso-level-number-format:roman-lower; mso-level-tab-stop:none; mso-level-number-position:right; text-indent:-9.0pt;} @list l52:level4 {mso-level-tab-stop:144.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l52:level5 {mso-level-tab-stop:180.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l52:level6 {mso-level-tab-stop:216.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l52:level7 {mso-level-tab-stop:252.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l52:level8 {mso-level-tab-stop:288.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l52:level9 {mso-level-tab-stop:324.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l53 {mso-list-id:1142578106; mso-list-type:hybrid; mso-list-template-ids:2126051910 197641 197641 328713 66569 197641 328713 66569 197641 328713;} @list l53:level1 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:48.25pt; text-indent:-18.0pt; font-family:"Courier New";} @list l54 {mso-list-id:1165196460; mso-list-template-ids:1333577636;} @list l54:level1 {mso-level-start-at:3; mso-level-text:%1; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:18.0pt; text-indent:-18.0pt;} @list l54:level2 {mso-level-start-at:4; mso-level-text:"%1\.%2"; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:30.25pt; text-indent:-18.0pt;} @list l54:level3 {mso-level-text:"%1\.%2\.%3"; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:58.5pt; text-indent:-36.0pt;} @list l54:level4 {mso-level-text:"%1\.%2\.%3\.%4"; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:72.75pt; text-indent:-36.0pt;} @list l54:level5 {mso-level-text:"%1\.%2\.%3\.%4\.%5"; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:103.0pt; text-indent:-54.0pt;} @list l54:level6 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6"; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:115.25pt; text-indent:-54.0pt;} @list l54:level7 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7"; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:145.5pt; text-indent:-72.0pt;} @list l54:level8 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8"; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:157.75pt; text-indent:-72.0pt;} @list l54:level9 {mso-level-text:"%1\.%2\.%3\.%4\.%5\.%6\.%7\.%8\.%9"; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:170.0pt; text-indent:-72.0pt;} @list l55 {mso-list-id:1285304338; mso-list-type:hybrid; mso-list-template-ids:-1013518452 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l55:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l55:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:"Courier New";} @list l55:level3 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Wingdings;} @list l56 {mso-list-id:1422874227; mso-list-type:hybrid; mso-list-template-ids:1627428786 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l56:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l56:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:"Courier New";} @list l56:level3 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Wingdings;} @list l56:level4 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l57 {mso-list-id:1537690677; mso-list-type:hybrid; mso-list-template-ids:-1113179986 984073 1639433 1770505 984073 1639433 1770505 984073 1639433 1770505;} @list l57:level1 {mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt;} @list l57:level2 {mso-level-number-format:alpha-lower; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt;} @list l57:level3 {mso-level-number-format:roman-lower; mso-level-tab-stop:none; mso-level-number-position:right; text-indent:-9.0pt;} @list l58 {mso-list-id:1550989832; mso-list-type:hybrid; mso-list-template-ids:-1283547980 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l58:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l58:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:"Courier New";} @list l58:level3 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Wingdings;} @list l59 {mso-list-id:1591084245; mso-list-type:hybrid; mso-list-template-ids:536102064 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l59:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l59:level2 {mso-level-tab-stop:72.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l59:level3 {mso-level-tab-stop:108.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l59:level4 {mso-level-tab-stop:144.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l59:level5 {mso-level-tab-stop:180.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l59:level6 {mso-level-tab-stop:216.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l59:level7 {mso-level-tab-stop:252.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l59:level8 {mso-level-tab-stop:288.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l59:level9 {mso-level-tab-stop:324.0pt; mso-level-number-position:left; text-indent:-18.0pt;} @list l60 {mso-list-id:1621841122; mso-list-type:hybrid; mso-list-template-ids:189193450 984073 1639433 66569 984073 1639433 1770505 984073 1639433 1770505;} @list l60:level1 {mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt;} @list l60:level2 {mso-level-number-format:alpha-lower; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt;} @list l60:level3 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-9.0pt; font-family:Symbol;} @list l61 {mso-list-id:1654872454; mso-list-type:hybrid; mso-list-template-ids:1808590874 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l61:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l61:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:"Courier New";} @list l62 {mso-list-id:1741899881; mso-list-type:hybrid; mso-list-template-ids:1885754264 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l62:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:48.25pt; text-indent:-18.0pt; font-family:Symbol;} @list l63 {mso-list-id:1789271422; mso-list-type:hybrid; mso-list-template-ids:1291634162 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l63:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:54.0pt; text-indent:-18.0pt; font-family:Symbol;} @list l64 {mso-list-id:1860505182; mso-list-type:hybrid; mso-list-template-ids:-1608331772 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l64:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l65 {mso-list-id:1878929485; mso-list-type:hybrid; mso-list-template-ids:1972014580 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l65:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l66 {mso-list-id:1884175742; mso-list-type:hybrid; mso-list-template-ids:1919307920 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l66:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:39.0pt; text-indent:-18.0pt; font-family:Symbol;} @list l67 {mso-list-id:1898085571; mso-list-type:hybrid; mso-list-template-ids:1316922216 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l67:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:48.25pt; text-indent:-18.0pt; font-family:Symbol;} @list l68 {mso-list-id:1980525125; mso-list-type:hybrid; mso-list-template-ids:76730994 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l68:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l68:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:"Courier New";} @list l68:level3 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Wingdings;} @list l69 {mso-list-id:1983387484; mso-list-type:hybrid; mso-list-template-ids:-1582808340 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l69:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l70 {mso-list-id:2023169348; mso-list-type:hybrid; mso-list-template-ids:-753352340 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l70:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l71 {mso-list-id:2043817759; mso-list-type:hybrid; mso-list-template-ids:-1422620912 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l71:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l72 {mso-list-id:2080396385; mso-list-type:hybrid; mso-list-template-ids:-1998176346 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l72:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:48.25pt; text-indent:-18.0pt; font-family:Symbol;} @list l73 {mso-list-id:2087222992; mso-list-type:hybrid; mso-list-template-ids:-131306758 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l73:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:Symbol;} @list l73:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-18.0pt; font-family:"Courier New";} @list l74 {mso-list-id:2128817889; mso-list-type:hybrid; mso-list-template-ids:1607383380 66569 197641 328713 66569 197641 328713 66569 197641 328713;} @list l74:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; margin-left:48.25pt; text-indent:-18.0pt; font-family:Symbol;} @list l50:level1 lfo2 {mso-level-start-at:0;} @list l50:level2 lfo2 {mso-level-start-at:0;} @list l50:level3 lfo2 {mso-level-start-at:0;} @list l50:level4 lfo2 {mso-level-start-at:0;} @list l50:level5 lfo2 {mso-level-start-at:0;} @list l50:level6 lfo2 {mso-level-start-at:0;} @list l24:level1 lfo22 {mso-level-start-at:0;} @list l59:level1 lfo28 {mso-level-start-at:0;} @list l17:level1 lfo44 {mso-level-start-at:0;} @list l17:level2 lfo44 {mso-level-start-at:0;} ol {margin-bottom:0pt;} ul {margin-bottom:0pt;} --> </style> <!--[if gte mso 9]><xml> <o:shapedefaults v:ext="edit" spidmax="2050"/> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext="edit"> <o:idmap v:ext="edit" data="1"/> </o:shapelayout></xml><![endif]--> </head> <body bgcolor=white lang=EN-US link=blue vlink=purple style='tab-interval:36.0pt'> <div class=Section1> <p class=MsoTitle>Scalable Access Controls for Lineage</p> <p class=Authornames>Arnon Rosenthal, Len Seligman, Adriane Chapman, Barbara Blaustein</p> <p class=AuthorAffiliation>The MITRE Corporation </p> <p class=AuthorAffiliation>Bedford MA, McLean VA <br> <span class=E-mailSignatureChar>{arnie, seligman, achapman, bblaustein}@mitre.org</span></p> </div> <span style='font-size:12.0pt;font-family:"Times New Roman";mso-ansi-language: EN-US'><i><br clear=ALL style='page-break-before:auto;mso-break-type:section-break'> </i></span> <div class=Section2> <p class=AbstractHeading>Abstract</p> <p class=NormalPost-Header>Lineage stores often contain sensitive information that needs protection from unauthorized access. We build on prior work for security and privacy of lineage information, focusing on complex conditions and scalable administration. We use Attribute-Based Access Control (ABAC) to express conditions based on many <i>attributes</i><span style='font-style:normal'>, instead of roles. We then make administration and management more scalable, instead of managing large, monolithic access predicates for each object.<span style="mso-spacerun: yes">&nbsp; </span>To do so, we first support modular traceability and maintainability for separate concerns (e.g. security, legally mandated privacy, organizationally mandated privacy).<span style="mso-spacerun: yes">&nbsp; </span>We then provide constructs to manage authority when multiple administrators must collaborate. We show that these security techniques are needed for easy lineage security administration.</span></p> <h1><a name="_Ref216497170"><![if !supportLists]>1. <![endif]>Introduction</a></h1> <p class=NormalPost-Header>Several papers have noted that lineage (also known as provenance) information may often contain sensitive information that must be protected, e.g. <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE <span style='mso-element: field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE.DATA <![if gte mso 9]><xml> <w:data>3C456E644E6F74653E3C436974653E3C417574686F723E486173616E3C2F417574686F723E3C596561723E323030373C2F596561723E3C5265634E756D3E3735323C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3735323C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3735323C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E486173616E2C20522E3C2F617574686F723E3C617574686F723E53696F6E2C20522E3C2F617574686F723E3C617574686F723E57696E736C6574742C204D2E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E496E74726F647563696E67205365637572652050726F76656E616E63653A2050726F626C656D7320616E64204368616C6C656E6765733C2F7469746C653E3C7365636F6E646172792D7469746C653E50726F63656564696E6773206F662074686520546869726420496E7465726E6174696F6E616C20576F726B73686F70206F6E2053746F7261676520536563757269747920616E64205375727669766162696C6974793C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C64617465733E3C796561723E323030373C2F796561723E3C2F64617465733E3C6C6162656C3E686173616E30373C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E427261756E3C2F417574686F723E3C596561723E323030383C2F596561723E3C5265634E756D3E3737393C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3737393C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3737393C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D22436F6E666572656E63652050726F63656564696E6773223E31303C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E55726920427261756E3C2F617574686F723E3C617574686F723E417661726168616D205368696E6E61723C2F617574686F723E3C617574686F723E4D6172676F2053656C747A65723C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E5365637572696E672050726F76656E616E63653C2F7469746C653E3C7365636F6E646172792D7469746C653E5553454E495820486F745365633C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C64617465733E3C796561723E323030383C2F796561723E3C2F64617465733E3C75726C733E3C2F75726C733E3C637573746F6D323E323030383C2F637573746F6D323E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E54616E3C2F417574686F723E3C596561723E323030363C2F596561723E3C5265634E756D3E3732343C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3732343C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3732343C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D22436F6E666572656E63652050726F63656564696E6773223E31303C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E54616E2C20562E3C2F617574686F723E3C617574686F723E47726F74682C20502E3C2F617574686F723E3C617574686F723E4D696C65732C20532E3C2F617574686F723E3C617574686F723E4A69616E672C20532E3C2F617574686F723E3C617574686F723E4D756E726F652C20532E3C2F617574686F723E3C617574686F723E54736173616B6F752C20532E3C2F617574686F723E3C617574686F723E4D6F726561752C204C2E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E53656375726974792049737375657320696E206120534F412D42617365642050726F76656E616E63652053797374656D3C2F7469746C653E3C616C742D7469746C653E4C656374757265204E6F74657320696E20436F6D707574657220536369656E63653C2F616C742D7469746C653E3C2F7469746C65733E3C616C742D706572696F646963616C3E3C66756C6C2D7469746C653E4C656374757265204E6F74657320696E20436F6D707574657220536369656E63653C2F66756C6C2D7469746C653E3C2F616C742D706572696F646963616C3E3C64617465733E3C796561723E323030363C2F796561723E3C2F64617465733E3C7075626C69736865723E537072696E676572204265726C696E202F2048656964656C626572673C2F7075626C69736865723E3C6C6162656C3E74616E30363C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C2F456E644E6F74653E</w:data> </xml><![endif]><span style='mso-element:field-end'></span><span style='mso-element:field-separator'></span><![endif]-->[8, 18, 29]<!--[if gte mso 9]><xml> <w:data>3C456E644E6F74653E3C436974653E3C417574686F723E486173616E3C2F417574686F723E3C596561723E323030373C2F596561723E3C5265634E756D3E3735323C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3735323C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3735323C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E486173616E2C20522E3C2F617574686F723E3C617574686F723E53696F6E2C20522E3C2F617574686F723E3C617574686F723E57696E736C6574742C204D2E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E496E74726F647563696E67205365637572652050726F76656E616E63653A2050726F626C656D7320616E64204368616C6C656E6765733C2F7469746C653E3C7365636F6E646172792D7469746C653E50726F63656564696E6773206F662074686520546869726420496E7465726E6174696F6E616C20576F726B73686F70206F6E2053746F7261676520536563757269747920616E64205375727669766162696C6974793C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C64617465733E3C796561723E323030373C2F796561723E3C2F64617465733E3C6C6162656C3E686173616E30373C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E427261756E3C2F417574686F723E3C596561723E323030383C2F596561723E3C5265634E756D3E3737393C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3737393C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3737393C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D22436F6E666572656E63652050726F63656564696E6773223E31303C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E55726920427261756E3C2F617574686F723E3C617574686F723E417661726168616D205368696E6E61723C2F617574686F723E3C617574686F723E4D6172676F2053656C747A65723C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E5365637572696E672050726F76656E616E63653C2F7469746C653E3C7365636F6E646172792D7469746C653E5553454E495820486F745365633C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C64617465733E3C796561723E323030383C2F796561723E3C2F64617465733E3C75726C733E3C2F75726C733E3C637573746F6D323E323030383C2F637573746F6D323E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E54616E3C2F417574686F723E3C596561723E323030363C2F596561723E3C5265634E756D3E3732343C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3732343C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3732343C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D22436F6E666572656E63652050726F63656564696E6773223E31303C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E54616E2C20562E3C2F617574686F723E3C617574686F723E47726F74682C20502E3C2F617574686F723E3C617574686F723E4D696C65732C20532E3C2F617574686F723E3C617574686F723E4A69616E672C20532E3C2F617574686F723E3C617574686F723E4D756E726F652C20532E3C2F617574686F723E3C617574686F723E54736173616B6F752C20532E3C2F617574686F723E3C617574686F723E4D6F726561752C204C2E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E53656375726974792049737375657320696E206120534F412D42617365642050726F76656E616E63652053797374656D3C2F7469746C653E3C616C742D7469746C653E4C656374757265204E6F74657320696E20436F6D707574657220536369656E63653C2F616C742D7469746C653E3C2F7469746C65733E3C616C742D706572696F646963616C3E3C66756C6C2D7469746C653E4C656374757265204E6F74657320696E20436F6D707574657220536369656E63653C2F66756C6C2D7469746C653E3C2F616C742D706572696F646963616C3E3C64617465733E3C796561723E323030363C2F796561723E3C2F64617465733E3C7075626C69736865723E537072696E676572204265726C696E202F2048656964656C626572673C2F7075626C69736865723E3C6C6162656C3E74616E30363C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C2F456E644E6F74653E</w:data> </xml><![endif]--><!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->, and a few have described access control mechanisms appropriate for lineage data <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Chebotko&lt;/Author&gt;&lt;Year&gt;2008&lt;/Year&gt;&lt;RecNum&gt;723&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;723&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;723&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Chebotko, Artem&lt;/author&gt;&lt;author&gt;Chang, Seunghan&lt;/author&gt;&lt;author&gt;Lu, Shiyong&lt;/author&gt;&lt;author&gt;Fotouhi, Farshad&lt;/author&gt;&lt;author&gt;Yang, Ping&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Scientific Workflow Provenance Querying with Security Views&lt;/title&gt;&lt;secondary-title&gt;WAIM&lt;/secondary-title&gt;&lt;/titles&gt;&lt;dates&gt;&lt;year&gt;2008&lt;/year&gt;&lt;/dates&gt;&lt;label&gt;chebotko08&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;Cite&gt;&lt;Author&gt;Braun&lt;/Author&gt;&lt;Year&gt;2006&lt;/Year&gt;&lt;RecNum&gt;778&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;778&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;778&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Unpublished Work&quot;&gt;34&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Uri Braun&lt;/author&gt;&lt;author&gt;Avi Shinnar&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;A Security Model for Provenance&lt;/title&gt;&lt;secondary-title&gt;Technical Report&lt;/secondary-title&gt;&lt;/titles&gt;&lt;volume&gt;TR-04-06&lt;/volume&gt;&lt;dates&gt;&lt;year&gt;2006&lt;/year&gt;&lt;/dates&gt;&lt;publisher&gt;Harvard University Computer Science&lt;/publisher&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;Cite&gt;&lt;Author&gt;Braun&lt;/Author&gt;&lt;Year&gt;2008&lt;/Year&gt;&lt;RecNum&gt;779&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;779&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;779&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Conference Proceedings&quot;&gt;10&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Uri Braun&lt;/author&gt;&lt;author&gt;Avaraham Shinnar&lt;/author&gt;&lt;author&gt;Margo Seltzer&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Securing Provenance&lt;/title&gt;&lt;secondary-title&gt;USENIX HotSec&lt;/secondary-title&gt;&lt;/titles&gt;&lt;dates&gt;&lt;year&gt;2008&lt;/year&gt;&lt;/dates&gt;&lt;urls&gt;&lt;/urls&gt;&lt;custom2&gt;2008&lt;/custom2&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[7, 8, 12]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->. This paper focuses on managing the access policies on nodes, edges, and properties of a lineage graph. We extend the prior work with these contributions:</p> <p class=ListParagraph style='margin-left:21.6pt;text-indent:-18.0pt; mso-list:l11 level1 lfo45'><![if !supportLists]><span style='font-family:Symbol'>&middot;<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]>We allow finer-grained policies&#8212;i.e. for particular properties of an individual lineage node or edge&#8212;and illustrate their importance. We also categorize properties in a way that helps assign administrators for parts of a policy.</p> <p class=ListParagraph style='margin-left:21.6pt;text-indent:-18.0pt; mso-list:l11 level1 lfo45'><![if !supportLists]><span style='font-family:Symbol'>&middot;<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]>We base our model on attribute-based access control (ABAC). Unlike role-based access control (RBAC), the predominant model in prior lineage security work, ABAC can express general access predicates, referencing any available attribute information in the environment. </p> <p class=ListParagraph style='margin-left:21.6pt;text-indent:-18.0pt; mso-list:l11 level1 lfo45'><![if !supportLists]><span style='font-family:Symbol'>&middot;<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]>We enhance modularity of ABAC by adding a model for separate capture and combination of multiple concerns. The explicit decomposition of access predicates makes them easier to understand, maintain, and trace to specific concerns. We illustrate its applicability to lineage security and describe key stakeholder roles for lineage scenarios drawn from enterprise applications. </p> <p class=ListParagraph style='margin-left:21.6pt;text-indent:-18.0pt; mso-list:l11 level1 lfo45'><![if !supportLists]><span style='font-family:Symbol'>&middot;<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]>We provide a way to manage split authority, where different concerns (or <i>stakes</i><span style='font-style:normal'>) are managed by different people (</span><i>stakeholders</i><span style='font-style: normal'>).</span></p> <p class=MsoNormal>Following the conventions of the Open Prov<b>e</b><span style='font-weight:normal'>nance Model (OPM) </span><!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Moreau&lt;/Author&gt;&lt;Year&gt;2007&lt;/Year&gt;&lt;RecNum&gt;573&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;573&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;573&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Report&quot;&gt;27&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Moreau, L.&lt;/author&gt;&lt;author&gt;Freire, J.&lt;/author&gt;&lt;author&gt;Futrelle, J.&lt;/author&gt;&lt;author&gt;McGrath, R.&lt;/author&gt;&lt;author&gt;Myers, J.&lt;/author&gt;&lt;author&gt;Paulson, P.&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;The Open Provenance Model&lt;/title&gt;&lt;/titles&gt;&lt;dates&gt;&lt;year&gt;2007&lt;/year&gt;&lt;/dates&gt;&lt;publisher&gt;University of Southampton&lt;/publisher&gt;&lt;label&gt;provmodelreport&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[22]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->, data (artifacts) and processes are represented by nodes; each edge represents a relationship (e.g. generatedBy). Edges represent causality and point <i>inverse</i><span style='font-style:normal'> to data flow; they may also be labeled with specific roles, e.g. input_arg_X.</span></p> <p class=MsoNormal><b>Example:</b><span style='font-weight:normal'> Consider the lineage graph in Figure 1, which shows the data (ovals) and processes (rectangles) used to produce an Emergency Preparedness Office&#8217;s (EPO) Epidemic Warning Report (dashed outline). Mary, a Health Department recipient of an epidemic warning report wants to know how it was produced in order to know how to best interpret it, whether to trust it for her purposes, etc.</span></p> <p class=MsoNormal>However, in determining which parts of the lineage graph to reveal to Mary, the lineage system should consider several stakeholders&#8217; interests. For example, the provider of animal test data may want funding agencies to know he contributed to the intelligence report, but may not want the public to know. This same investigator demands that high- level approvals be required to release the edge with role &#8220;Animal_Tests&#8221;. Additionally, the properties of a lineage node may contain even more sensitive information. For instance, while most cleared analysts can see the BioThreat Intelligence report node, the authoring agent&#8217;s identity should be protected by only releasing this data to a very restricted group of users. </p> <p class=MsoNormal>The requirement to protect specific properties of a node, such as the author of a report or invoker of an execution, illustrates the need for fine-grained access controls; treating a given node or edge as a monolith is often inadequate. There may also be conflicts among interested parties about how restricted the lineage information should be. For example, the author of the Epidemic Projector, Prof. Jones, may claim that the information about the algorithm should be visible to anyone, while Analyst Smith, the invoker of the program, wishes this particular use to be considered extremely sensitive. Thus, any security model must allow both Analyst Smith and Professor Jones to express their concerns, and determine how best to honor them. A good model will let each of them reexamine and edit their concerns, and regenerate the access predicates.</p> <p class=MsoNormal>Unfortunately, current access control mechanisms are too hard to administer where there are multiple stakeholder concerns about a single object. An administrator must consider all the relevant stakeholders&#8217; concerns and define the complicated policies that combine them. Importantly, the separate concerns are not currently modeled. The resulting composite policies are not modular; they lack traceability; they&#8217;re difficult to understand and edit, and they&#8217;re not well-suited to gap analysis. For example, suppose access to lineage information about Animal Testing depends on the following predicate (the arguments are discussed in Section <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>REF _Ref216173402 \r <span style='mso-element:field-separator'></span><![endif]-->3.1<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->):<span style="mso-spacerun: yes">&nbsp; </span></p> <p class=MsoNormal style='text-indent:0pt'><i><![if !supportEmptyParas]>&nbsp;<![endif]><o:p></o:p></i></p> <p class=MsoNormal style='text-indent:0pt'><i><![if !supportEmptyParas]>&nbsp;<![endif]><o:p></o:p></i></p> <p class=MsoNormal style='text-indent:0pt'><i><![if !supportEmptyParas]>&nbsp;<![endif]><o:p></o:p></i></p> <p class=MsoNormal style='text-indent:0pt'><i>Animal_Testing_Access</i><span style='font-style:normal'>(user, resource, environment) </span><span style='font-family:"Cambria Math"'>&#8788; [User.Division=&nbsp;Intelligence&nbsp;</span><span style='font-family:Symbol;mso-char-type:symbol;mso-symbol-font-family:Symbol'><span style='mso-char-type:symbol;mso-symbol-font-family:Symbol'>&Ugrave;</span></span><span style='font-family:"Cambria Math"'><o:p></o:p></span></p> <p class=MsoNormal align=left style='margin-top:0pt;margin-right:14.4pt; margin-bottom:0pt;margin-left:19.45pt;margin-bottom:.0001pt;text-align:left; text-indent:-7.2pt'><span style='font-family:"Cambria Math"'>User.AssignedProject.Type=Epidemiology </span><span style='font-family:Symbol;mso-char-type:symbol;mso-symbol-font-family: Symbol'><span style='mso-char-type:symbol;mso-symbol-font-family:Symbol'>&and;</span></span><span style='font-family:"Cambria Math"'><o:p></o:p></span></p> <p class=MsoNormal align=left style='margin-right:14.4pt;text-align:left'><span style='font-family:"Cambria Math"'>Request.SourceDomain&nbsp;is in {.gov, .mil}&nbsp;</span><span style='font-family:Symbol;mso-char-type:symbol; mso-symbol-font-family:Symbol'><span style='mso-char-type:symbol;mso-symbol-font-family: Symbol'>&and;</span></span><span style='font-family:"Cambria Math"'><o:p></o:p></span></p> <p class=MsoNormal align=left style='margin-right:14.4pt;text-align:left'><span style='font-family:"Cambria Math"'>Experiment.ReleaseMarking =<span style="mso-spacerun: yes">&nbsp; </span>Intel&nbsp;</span><span style='font-family:Symbol;mso-char-type:symbol;mso-symbol-font-family:Symbol'><span style='mso-char-type:symbol;mso-symbol-font-family:Symbol'>&and;</span></span><span style='font-family:"Cambria Math"'><o:p></o:p></span></p> <p class=MsoNormal align=left style='margin-right:14.4pt;text-align:left'><span style='font-family:"Cambria Math"'>(ExperSubject.Type = inanimate&nbsp;</span><span style='font-family:Symbol;mso-char-type:symbol;mso-symbol-font-family:Symbol'><span style='mso-char-type:symbol;mso-symbol-font-family:Symbol'>&or;</span></span><span style='font-family:"Cambria Math"'><o:p></o:p></span></p> <p class=MsoNormal align=left style='margin-right:14.4pt;text-align:left'><span style='font-family:"Cambria Math"'>ExperSubject.Type = animal </span><span style='font-family:Symbol;mso-char-type:symbol;mso-symbol-font-family:Symbol'><span style='mso-char-type:symbol;mso-symbol-font-family:Symbol'>&and;</span></span><span style='font-family:"Cambria Math"'> <o:p></o:p></span></p> <p class=MsoNormal align=left style='margin-right:14.4pt;text-align:left'><span style='font-family:"Cambria Math"'><span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>experimenterName.pseudonym=true </span><span style='font-family:Symbol; mso-char-type:symbol;mso-symbol-font-family:Symbol'><span style='mso-char-type: symbol;mso-symbol-font-family:Symbol'>&or;</span></span><span style='font-family:"Cambria Math"'><o:p></o:p></span></p> <p class=MsoNormal align=left style='margin-right:14.4pt;text-align:left'><span style='font-family:"Cambria Math"'>ExperSubject.Type = human </span><span style='font-family:Symbol;mso-char-type:symbol;mso-symbol-font-family:Symbol'><span style='mso-char-type:symbol;mso-symbol-font-family:Symbol'>&and;</span></span><span style='font-family:"Cambria Math"'> <o:p></o:p></span></p> <p class=MsoNormal align=left style='margin-top:0pt;margin-right:14.4pt; margin-bottom:0pt;margin-left:12.25pt;margin-bottom:.0001pt;text-align:left; text-indent:0pt'><span style='font-family:"Cambria Math"'><span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>releaseOnFile(ExperSubject) <o:p></o:p></span></p> <p class=MsoNormal align=left style='margin-right:14.4pt;text-align:left; text-indent:0pt'><span style='font-family:Symbol;mso-char-type:symbol; mso-symbol-font-family:Symbol'><span style='mso-char-type:symbol;mso-symbol-font-family: Symbol'>&or;</span></span><span style='font-family:"Cambria Math"'><span style="mso-spacerun: yes">&nbsp; </span>[Request.HasApproval.Level &#8805; 4 </span><span style='font-family:Symbol;mso-char-type:symbol;mso-symbol-font-family:Symbol'><span style='mso-char-type:symbol;mso-symbol-font-family:Symbol'>&or;</span></span><span style='font-family:"Cambria Math"'><o:p></o:p></span></p> <p class=MsoNormal align=left style='margin-right:14.4pt;text-align:left'><span style='font-family:"Cambria Math"'>(Request.HasApproval.Level &#8805; 2 </span><span style='font-family:Symbol;mso-char-type:symbol;mso-symbol-font-family:Symbol'><span style='mso-char-type:symbol;mso-symbol-font-family:Symbol'>&and;</span></span><span style='font-family:"Cambria Math"'><o:p></o:p></span></p> <p class=MsoNormal align=left style='margin-right:14.4pt;text-align:left'><span style='font-family:"Cambria Math"'><span style="mso-spacerun: yes">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>threat.Status = Red)]<o:p></o:p></span></p> <div style='mso-element:frame;mso-element-frame-width:223.2pt;mso-element-frame-height: 185.05pt;mso-element-frame-hspace:9.35pt;mso-element-wrap:around;mso-element-anchor-vertical: paragraph;mso-element-anchor-horizontal:page;mso-element-left:81.4pt; mso-element-top:.05pt;mso-height-rule:exactly'> <table cellspacing=0 cellpadding=0 hspace=0 vspace=0 width=232 height=185 align=left> <tr> <td valign=top align=left height=185 style='padding-top:0pt;padding-right: 9.35pt;padding-bottom:0pt;padding-left:9.35pt'> <p class=MsoNormal style='page-break-after:avoid;mso-element:frame; mso-element-frame-width:223.2pt;mso-element-frame-height:185.05pt;mso-element-frame-hspace: 9.35pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph; mso-element-anchor-horizontal:page;mso-element-left:81.4pt;mso-element-top: .05pt;mso-height-rule:exactly'><a name="_Ref216412765"><!--[if gte vml 1]><v:shapetype id="_x0000_t75" coordsize="21600,21600" o:spt="75" o:preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f"> <v:stroke joinstyle="miter"/> <v:formulas> <v:f eqn="if lineDrawn pixelLineWidth 0"/> <v:f eqn="sum @0 1 0"/> <v:f eqn="sum 0 0 @1"/> <v:f eqn="prod @2 1 2"/> <v:f eqn="prod @3 21600 pixelWidth"/> <v:f eqn="prod @3 21600 pixelHeight"/> <v:f eqn="sum @0 0 1"/> <v:f eqn="prod @6 1 2"/> <v:f eqn="prod @7 21600 pixelWidth"/> <v:f eqn="sum @8 21600 0"/> <v:f eqn="prod @7 21600 pixelHeight"/> <v:f eqn="sum @10 21600 0"/> </v:formulas> <v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect"/> <o:lock v:ext="edit" aspectratio="t"/> </v:shapetype><v:shape id="_x0000_i1025" type="#_x0000_t75" style='width:211pt; height:157pt' o:ole=""> <v:imagedata src="index_files/image001.gif" o:althref="index_files/image002.emf" o:title=""/> </v:shape><![endif]--><![if !vml]><img width=281 height=209 src="index_files/image003.png" v:shapes="_x0000_i1025"><![endif]><!--[if gte mso 9]><xml> <o:OLEObject Type="Embed" ProgID="PowerPoint.Slide.8" ShapeID="_x0000_i1025" DrawAspect="Content" ObjectID="_1170316877"> </o:OLEObject> </xml><![endif]--></a></p> <p class=MsoCaption style='text-align:justify;line-height:normal;mso-element: frame;mso-element-frame-width:223.2pt;mso-element-frame-height:185.05pt; mso-element-frame-hspace:9.35pt;mso-element-wrap:around;mso-element-anchor-vertical: paragraph;mso-element-anchor-horizontal:page;mso-element-left:81.4pt; mso-element-top:.05pt;mso-height-rule:exactly'><span style='mso-bookmark: _Ref216412765'><span style='font-size:9.0pt;font-family:Arial'>Figure 1: Lineage Graph for EPO Epidemic Warning Reports.<o:p></o:p></span></span></p> </td> </tr> </table> </div> <span style='mso-bookmark:_Ref216412765'></span> <p class=MsoNormal>This predicate exploits a wide variety of knowledge about the request, coming from multiple sources. It is hard to imagine encompassing it all in a role hierarchy. There are several categories of concerns here, such as government secrecy, experimental subject privacy, and experimenter privacy. Even within categories, some stem from agency-wide substantive policy (e.g. do not release outside the agency), others are aware of the sort of information this is (only epidemiologists have access), and some are because an authority has insisted on crisis workarounds (the disjuncts at the end).</p> <p class=MsoNormal>In such an environment, a lineage service exists mainly to let users execute queries over the lineage graph, e.g. to find all predecessors and successors of a node, while applying various predicates and projections. <i>Lineage security</i><span style='font-style:normal'> ensures that each query executes on a database subset, i.e. nodes, edges, and property values for which the request satisfies the access control predicates. Previous researchers have described basic capabilities, but have not addressed three more advanced requirements:</span></p> <p class=MsoNormal>First, the access predicate on a node, edge, or property may involve multiple subexpressions, dependent on different attributes of users, the resource, and the environment. Role-based access control is not easily extended to support this. </p> <p class=MsoNormal>Second, the predicate may include terms representing many distinct concerns that ought to be managed modularly, such as security, legally mandated privacy, and organizationally mandated privacy. If one of these concerns changes, or if compliance is being audited, we do not want to wade through a 12-line predicate.</p> <p class=MsoNormal>Third, there may be multiple stakeholders involved in setting the policy on a protected item, and it is necessary to govern how the different desires are to be combined. For example, if privacy officers want only doctors to see certain information, and existing workflows require that it be available to financial managers, how does the system help administrators manage these conflicting relationships? </p> <p class=MsoNormal>Any access control system for lineage must allow the following: determine access based on values of multiple attributes; handle multiple goals, each with separately evolving tradeoffs and legal requirements; and appropriately combine the all stakeholders&#8217; concerns.</p> <p class=MsoNormal>One obvious but inadequate solution is to appoint a lineage system administrator. However, the stakeholders whose systems supply the lineage data may not be willing to give this person discretion to make substantive policy decisions. In our experience, the lineage service is often a political lightweight, not an 800-pound gorilla.<span style="mso-spacerun: yes">&nbsp; </span>Also, the appointment of an administrator does not make the problems of stakeholder conflicts and concern management go away, nor does it give the administrator guidance on how to resolve them. </p> <div style='mso-element:frame;mso-element-frame-height:196.55pt;mso-element-frame-hspace: 9.35pt;mso-element-wrap:around;mso-element-anchor-vertical:page;mso-element-anchor-horizontal: page;mso-element-left:73.2pt;mso-element-top:108.55pt;mso-height-rule:exactly'> <table cellspacing=0 cellpadding=0 hspace=0 vspace=0 height=197 align=left> <tr> <td valign=top align=left height=197 style='padding-top:0pt;padding-right: 9.35pt;padding-bottom:0pt;padding-left:9.35pt'> <p class=MsoNormal align=center style='text-align:center;page-break-after: avoid;mso-element:frame;mso-element-frame-height:196.55pt;mso-element-frame-hspace: 9.35pt;mso-element-wrap:around;mso-element-anchor-vertical:page;mso-element-anchor-horizontal: page;mso-element-left:73.2pt;mso-element-top:108.55pt;mso-height-rule:exactly'><!--[if gte vml 1]><v:shape id="_x0000_i1026" type="#_x0000_t75" style='width:220pt;height:165pt' o:ole=""> <v:imagedata src="index_files/image004.gif" o:althref="index_files/image005.emf" o:title=""/> </v:shape><![endif]--><![if !vml]><img width=293 height=220 src="index_files/image006.png" v:shapes="_x0000_i1026"><![endif]><!--[if gte mso 9]><xml> <o:OLEObject Type="Embed" ProgID="PowerPoint.Slide.8" ShapeID="_x0000_i1026" DrawAspect="Content" ObjectID="_1170316878"> </o:OLEObject> </xml><![endif]--></p> <p class=MsoCaption style='line-height:normal;mso-element:frame;mso-element-frame-height: 196.55pt;mso-element-frame-hspace:9.35pt;mso-element-wrap:around;mso-element-anchor-vertical: page;mso-element-anchor-horizontal:page;mso-element-left:73.2pt;mso-element-top: 108.55pt;mso-height-rule:exactly'><a name="_Ref216068410"><span style='font-size:9.0pt'>Figure </span></a><span style='font-size:9.0pt'>2: An example system architecture. Lineage storage and access control are on the right.<o:p></o:p></span></p> </td> </tr> </table> </div> <p class=MsoNormal>When faced with complex expressions, current access control mechanisms lack <i>traceability </i><span style='font-style:normal'>and </span><i>maintainability, </i><span style='font-style:normal'>i.e. they do not connect clauses in the predicate to the concern that motivated them, nor do they help an administrator focus only on the relevant portion when editing predicates. For example, the system should be able to show which clauses in the predicate exist to protect patient privacy vs. experimenter protection vs. national security. If a privacy regulation changes, we want a capability to edit just the relevant sub-specifications. When the HIPAA</span><a style='mso-footnote-id:ftn1' href="#_ftn1" name="_ftnref1" title=""><span class=MsoFootnoteReference><span style='font-family:Times'><span style='mso-special-character:footnote'><![if !supportFootnotes]>[1]<![endif]></span></span></span></a> auditors arrive, we want to highlight the controls motivated by patient privacy. If HIPAA rules change, we want to edit this portion without needing to extract it from a dozen other clauses. </p> <p class=MsoNormal>We lay out our system model in Section 2. In Section 3, we begin by showing how a general purpose attribute-based access control capability can support fine-grained access control for lineage data. We then extend vanilla ABAC to provide better maintainability, traceability, and sharing of authority, and show how this fits the needs of lineage. Section 4 discusses related work, and Section 5 describes our ongoing efforts to implement these ideas and areas for future research.</p> <h1><a name="_Ref215803411"></a><a name="_Ref215815188"><span style='mso-bookmark: _Ref215803411'><![if !supportLists]>2. <![endif]>High-Level Architecture</span></a></h1> <p class=MsoNormal>As users go about their ordinary tasks, creating or manipulating data on base systems, information about their actions is reported to the lineage store in ways that minimize intrusion on the <i>base </i><span style='font-style:normal'>(i.e. application) systems </span><!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE <span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE.DATA <![if gte mso 9]><xml> <w:data>3C456E644E6F74653E3C436974653E3C417574686F723E43616C6C6168616E3C2F417574686F723E3C596561723E323030363C2F596561723E3C5265634E756D3E3538383C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3538383C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3538383C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E43616C6C6168616E2C2053746576656E20502E3C2F617574686F723E3C617574686F723E4672656972652C204A756C69616E613C2F617574686F723E3C617574686F723E53616E746F732C20456D616E75656C653C2F617574686F723E3C617574686F723E53636865696465676765722C204361726C6F7320452E3C2F617574686F723E3C617574686F723E566F2C20436CC3A17564696F20542E2053696C7661616E642048757920542E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E566973547261696C733A2056697375616C697A6174696F6E206D656574732044617461204D616E6167656D656E743C2F7469746C653E3C7365636F6E646172792D7469746C653E5349474D4F443C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E3734352D3734373C2F70616765733E3C64617465733E3C796561723E323030363C2F796561723E3C2F64617465733E3C6C6162656C3E66726569726530363C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E4461766964736F6E3C2F417574686F723E3C596561723E323030373C2F596561723E3C5265634E756D3E3539333C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3539333C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3539333C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E4461766964736F6E2C20537573616E3C2F617574686F723E3C617574686F723E436F68656E2D426F756C616B69612C2053617261683C2F617574686F723E3C617574686F723E4579616C2C20416E61743C2F617574686F723E3C617574686F723E4C75646173636865722C204265727472616D3C2F617574686F723E3C617574686F723E4D635068696C6C6970732C2054696D6F7468793C2F617574686F723E3C617574686F723E426F776572732C20536861776E3C2F617574686F723E3C617574686F723E4672656972652C204A756C69616E613C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E50726F76656E616E636520696E20536369656E746966696320576F726B666C6F772053797374656D733C2F7469746C653E3C7365636F6E646172792D7469746C653E49454545204461746120456E67696E656572696E672042756C6C6574696E3C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E34342D35303C2F70616765733E3C766F6C756D653E33323C2F766F6C756D653E3C6E756D6265723E343C2F6E756D6265723E3C64617465733E3C796561723E323030373C2F796561723E3C2F64617465733E3C6C6162656C3E6461766964736F6E30373C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E467265773C2F417574686F723E3C596561723E323030383C2F596561723E3C5265634E756D3E3533313C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3533313C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3533313C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E467265772C204A616D65733C2F617574686F723E3C617574686F723E4D65747A6765722C20446F6D696E69633C2F617574686F723E3C617574686F723E536C617567687465722C2050657465723C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E4175746F6D61746963206361707475726520616E64207265636F6E737472756374696F6E206F6620636F6D7075746174696F6E616C2070726F76656E616E63653C2F7469746C653E3C7365636F6E646172792D7469746C653E436F6E637572722E20436F6D7075742E203A2050726163742E2045787065722E3C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E3438352D3439363C2F70616765733E3C766F6C756D653E32303C2F766F6C756D653E3C6E756D6265723E353C2F6E756D6265723E3C64617465733E3C796561723E323030383C2F796561723E3C2F64617465733E3C6C6162656C3E6672657730383C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E4F696E6E3C2F417574686F723E3C596561723E323030363C2F596561723E3C5265634E756D3E3537373C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3537373C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3537373C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E4F696E6E2C20546F6D3C2F617574686F723E3C617574686F723E477265656E776F6F642C204D61726B3C2F617574686F723E3C617574686F723E41646469732C204D6174746865773C2F617574686F723E3C617574686F723E416C7064656D69722C204D2E204E6564696D3C2F617574686F723E3C617574686F723E4665727269732C204A757374696E3C2F617574686F723E3C617574686F723E476C6F7665722C204B6576696E3C2F617574686F723E3C617574686F723E476F626C652C204361726F6C653C2F617574686F723E3C617574686F723E476F64657269732C20416E746F6F6E3C2F617574686F723E3C617574686F723E48756C6C2C2044756E63616E3C2F617574686F723E3C617574686F723E4D617276696E2C2044617272656E3C2F617574686F723E3C617574686F723E4C692C2050657465723C2F617574686F723E3C617574686F723E4C6F72642C205068696C6C69703C2F617574686F723E3C617574686F723E506F636F636B2C204D61747468657720522E3C2F617574686F723E3C617574686F723E53656E6765722C204D617274696E3C2F617574686F723E3C617574686F723E53746576656E732C20526F626572743C2F617574686F723E3C617574686F723E57697061742C20416E696C3C2F617574686F723E3C617574686F723E57726F652C2043687269733C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E54617665726E613A206C6573736F6E7320696E206372656174696E67206120776F726B666C6F7720656E7669726F6E6D656E7420666F7220746865206C69666520736369656E6365733A2052657365617263682041727469636C65733C2F7469746C653E3C7365636F6E646172792D7469746C653E436F6E637572722E20436F6D7075742E203A2050726163742E2045787065722E3C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E313036372D313130303C2F70616765733E3C766F6C756D653E31383C2F766F6C756D653E3C6E756D6265723E31303C2F6E756D6265723E3C64617465733E3C796561723E323030363C2F796561723E3C2F64617465733E3C6C6162656C3E74617665726E613C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C2F456E644E6F74653E</w:data> </xml><![endif]><span style='mso-element:field-end'></span><span style='mso-element:field-separator'></span><![endif]-->[10, 15, 17, 25]<!--[if gte mso 9]><xml> <w:data>3C456E644E6F74653E3C436974653E3C417574686F723E43616C6C6168616E3C2F417574686F723E3C596561723E323030363C2F596561723E3C5265634E756D3E3538383C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3538383C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3538383C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E43616C6C6168616E2C2053746576656E20502E3C2F617574686F723E3C617574686F723E4672656972652C204A756C69616E613C2F617574686F723E3C617574686F723E53616E746F732C20456D616E75656C653C2F617574686F723E3C617574686F723E53636865696465676765722C204361726C6F7320452E3C2F617574686F723E3C617574686F723E566F2C20436CC3A17564696F20542E2053696C7661616E642048757920542E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E566973547261696C733A2056697375616C697A6174696F6E206D656574732044617461204D616E6167656D656E743C2F7469746C653E3C7365636F6E646172792D7469746C653E5349474D4F443C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E3734352D3734373C2F70616765733E3C64617465733E3C796561723E323030363C2F796561723E3C2F64617465733E3C6C6162656C3E66726569726530363C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E4461766964736F6E3C2F417574686F723E3C596561723E323030373C2F596561723E3C5265634E756D3E3539333C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3539333C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3539333C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E4461766964736F6E2C20537573616E3C2F617574686F723E3C617574686F723E436F68656E2D426F756C616B69612C2053617261683C2F617574686F723E3C617574686F723E4579616C2C20416E61743C2F617574686F723E3C617574686F723E4C75646173636865722C204265727472616D3C2F617574686F723E3C617574686F723E4D635068696C6C6970732C2054696D6F7468793C2F617574686F723E3C617574686F723E426F776572732C20536861776E3C2F617574686F723E3C617574686F723E4672656972652C204A756C69616E613C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E50726F76656E616E636520696E20536369656E746966696320576F726B666C6F772053797374656D733C2F7469746C653E3C7365636F6E646172792D7469746C653E49454545204461746120456E67696E656572696E672042756C6C6574696E3C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E34342D35303C2F70616765733E3C766F6C756D653E33323C2F766F6C756D653E3C6E756D6265723E343C2F6E756D6265723E3C64617465733E3C796561723E323030373C2F796561723E3C2F64617465733E3C6C6162656C3E6461766964736F6E30373C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E467265773C2F417574686F723E3C596561723E323030383C2F596561723E3C5265634E756D3E3533313C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3533313C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3533313C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E467265772C204A616D65733C2F617574686F723E3C617574686F723E4D65747A6765722C20446F6D696E69633C2F617574686F723E3C617574686F723E536C617567687465722C2050657465723C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E4175746F6D61746963206361707475726520616E64207265636F6E737472756374696F6E206F6620636F6D7075746174696F6E616C2070726F76656E616E63653C2F7469746C653E3C7365636F6E646172792D7469746C653E436F6E637572722E20436F6D7075742E203A2050726163742E2045787065722E3C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E3438352D3439363C2F70616765733E3C766F6C756D653E32303C2F766F6C756D653E3C6E756D6265723E353C2F6E756D6265723E3C64617465733E3C796561723E323030383C2F796561723E3C2F64617465733E3C6C6162656C3E6672657730383C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E4F696E6E3C2F417574686F723E3C596561723E323030363C2F596561723E3C5265634E756D3E3537373C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3537373C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3537373C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E4F696E6E2C20546F6D3C2F617574686F723E3C617574686F723E477265656E776F6F642C204D61726B3C2F617574686F723E3C617574686F723E41646469732C204D6174746865773C2F617574686F723E3C617574686F723E416C7064656D69722C204D2E204E6564696D3C2F617574686F723E3C617574686F723E4665727269732C204A757374696E3C2F617574686F723E3C617574686F723E476C6F7665722C204B6576696E3C2F617574686F723E3C617574686F723E476F626C652C204361726F6C653C2F617574686F723E3C617574686F723E476F64657269732C20416E746F6F6E3C2F617574686F723E3C617574686F723E48756C6C2C2044756E63616E3C2F617574686F723E3C617574686F723E4D617276696E2C2044617272656E3C2F617574686F723E3C617574686F723E4C692C2050657465723C2F617574686F723E3C617574686F723E4C6F72642C205068696C6C69703C2F617574686F723E3C617574686F723E506F636F636B2C204D61747468657720522E3C2F617574686F723E3C617574686F723E53656E6765722C204D617274696E3C2F617574686F723E3C617574686F723E53746576656E732C20526F626572743C2F617574686F723E3C617574686F723E57697061742C20416E696C3C2F617574686F723E3C617574686F723E57726F652C2043687269733C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E54617665726E613A206C6573736F6E7320696E206372656174696E67206120776F726B666C6F7720656E7669726F6E6D656E7420666F7220746865206C69666520736369656E6365733A2052657365617263682041727469636C65733C2F7469746C653E3C7365636F6E646172792D7469746C653E436F6E637572722E20436F6D7075742E203A2050726163742E2045787065722E3C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E313036372D313130303C2F70616765733E3C766F6C756D653E31383C2F766F6C756D653E3C6E756D6265723E31303C2F6E756D6265723E3C64617465733E3C796561723E323030363C2F796561723E3C2F64617465733E3C6C6162656C3E74617665726E613C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C2F456E644E6F74653E</w:data> </xml><![endif]--><!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->.<span style="mso-spacerun: yes">&nbsp; </span><span style='mso-field-code:"REF _Ref216068410 \\* MERGEFORMAT"'>Figure </span>2 shows that the lineage storage, querying and access controls are separate from these base systems. Access controls on base systems are unaffected; the lineage store controls access to lineage information. The lineage store is logically unified but may be physically distributed.</p> <p class=MsoNormal>A lineage graph describes a series of process invocations, executed by one or more users, in pursuit of their various goals. We follow ES3 <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Frew&lt;/Author&gt;&lt;Year&gt;2008&lt;/Year&gt;&lt;RecNum&gt;531&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;531&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;531&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Frew, James&lt;/author&gt;&lt;author&gt;Metzger, Dominic&lt;/author&gt;&lt;author&gt;Slaughter, Peter&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Automatic capture and reconstruction of computational provenance&lt;/title&gt;&lt;secondary-title&gt;Concurr. Comput. : Pract. Exper.&lt;/secondary-title&gt;&lt;/titles&gt;&lt;pages&gt;485-496&lt;/pages&gt;&lt;volume&gt;20&lt;/volume&gt;&lt;number&gt;5&lt;/number&gt;&lt;dates&gt;&lt;year&gt;2008&lt;/year&gt;&lt;/dates&gt;&lt;label&gt;frew08&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[17]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]--> and PASS <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Muniswamy-Reddy&lt;/Author&gt;&lt;Year&gt;2006&lt;/Year&gt;&lt;RecNum&gt;552&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;552&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;552&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Muniswamy-Reddy, Kiran-Kumar&lt;/author&gt;&lt;author&gt;Holland, David A.&lt;/author&gt;&lt;author&gt;Braun, Uri&lt;/author&gt;&lt;author&gt;Seltzer, Margo I.&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Provenance-Aware Storage Systems&lt;/title&gt;&lt;secondary-title&gt;USENIX Annual Technical Conference&lt;/secondary-title&gt;&lt;/titles&gt;&lt;pages&gt;43-56&lt;/pages&gt;&lt;dates&gt;&lt;year&gt;2006&lt;/year&gt;&lt;/dates&gt;&lt;label&gt;muniswamy06&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[24]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]--> in that generation is <i>ad hoc &#8211; </i><span style='font-style:normal'>covering whatever was reported to the lineage system. Unlike traditional workflows (discussed in Section 3.4), the tasks, or steps, need not be defined prior to execution, so graphs may grow indefinitely and in unpredictable ways. In fact, information is tied together by data usage (i.e. graph connectivity), rather than by pre-defined patterns.</span></p> <div style='mso-element:frame;mso-element-frame-height:188.05pt;mso-element-frame-hspace: 9.35pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph; mso-element-anchor-horizontal:page;mso-element-left:80.45pt;mso-element-top: 5.05pt;mso-height-rule:exactly'> <table cellspacing=0 cellpadding=0 hspace=0 vspace=0 height=188 align=left> <tr> <td valign=top align=left height=188 style='padding-top:0pt;padding-right: 9.35pt;padding-bottom:0pt;padding-left:9.35pt'> <p class=MsoNormal style='page-break-after:avoid;mso-element:frame; mso-element-frame-height:188.05pt;mso-element-frame-hspace:9.35pt;mso-element-wrap: around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal: page;mso-element-left:80.45pt;mso-element-top:5.05pt;mso-height-rule:exactly'><!--[if gte vml 1]><v:shape id="_x0000_i1027" type="#_x0000_t75" style='width:209pt;height:157pt' o:ole=""> <v:imagedata src="index_files/image007.png" o:althref="index_files/image008.emf" o:title=""/> </v:shape><![endif]--><![if !vml]><img width=279 height=211 src="index_files/image007.png" v:shapes="_x0000_i1027"><![endif]><!--[if gte mso 9]><xml> <o:OLEObject Type="Embed" ProgID="PowerPoint.Slide.8" ShapeID="_x0000_i1027" DrawAspect="Content" ObjectID="_1170316880"> </o:OLEObject> </xml><![endif]--></p> <p class=MsoCaption style='text-align:justify;line-height:normal;mso-element: frame;mso-element-frame-height:188.05pt;mso-element-frame-hspace:9.35pt; mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal: page;mso-element-left:80.45pt;mso-element-top:5.05pt;mso-height-rule:exactly'><a name="_Ref222045094"></a><a name="_Ref222045073"><span style='mso-bookmark: _Ref222045094'><span style='font-size:9.0pt'>Figure </span></span></a><span style='mso-bookmark:_Ref222045073'><span style='font-size:9.0pt'>3: Properties and values for some nodes from Fig. 1.</span></span><span style='font-size:9.0pt'><o:p></o:p></span></p> </td> </tr> </table> </div> <p class=MsoNormal>A <i>lineage graph</i><span style='font-style:normal'> consists of a set of nodes, </span><i>N</i><span style='font-style:normal'>, and a set of edges, </span><i>E</i><span style='font-style:normal'>. As in </span><!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Braun&lt;/Author&gt;&lt;Year&gt;2008&lt;/Year&gt;&lt;RecNum&gt;779&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;779&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;779&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Conference Proceedings&quot;&gt;10&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Uri Braun&lt;/author&gt;&lt;author&gt;Avaraham Shinnar&lt;/author&gt;&lt;author&gt;Margo Seltzer&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Securing Provenance&lt;/title&gt;&lt;secondary-title&gt;USENIX HotSec&lt;/secondary-title&gt;&lt;/titles&gt;&lt;dates&gt;&lt;year&gt;2008&lt;/year&gt;&lt;/dates&gt;&lt;urls&gt;&lt;/urls&gt;&lt;custom2&gt;2008&lt;/custom2&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[8]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->, each object (node or edge) has descriptive properties that optionally appear on each node, as illustrated in <span style='mso-field-code:"REF _Ref222045094 \\* MERGEFORMAT"'>Figure </span>3. A lineage manager should predefine and categorize a starter set of properties, such as resource description, invocation time, etc.</p> <p class=MsoNormal>A <i>lineage query </i><span style='font-style:normal'>consists of edge traversal forward or backward from a start node (or node set), applying access predicates to node properties to determine which property values should be returned. </span></p> <p class=MsoNormal>Our security model protects objects (nodes and edges) and the values of their properties. These are called <i>protected items. </i><span style='font-style:normal'>There is an </span><i>access predicate</i><span style='font-style:normal'> that controls the visibility of each protected object and property.</span><a style='mso-footnote-id:ftn2' href="#_ftn2" name="_ftnref2" title=""><span class=MsoFootnoteReference><span style='font-family:Times'><sup><span style='mso-special-character:footnote'><![if !supportFootnotes]>[2]<![endif]></span></sup></span></span></a><sup> </sup>Edges which are not visible to a particular user are not traversed in executing lineage queries for that user. Thus, if the lineage graph contains three nodes that the user is entitled to see, but he is not entitled to see the edges between them, a query on that graph will return only the single start node. To aid security administration, we categorize properties into buckets that help determine default stakeholders.<span style="mso-spacerun: yes">&nbsp; </span></p> <p class=ListParagraph style='margin-left:21.6pt;text-indent:-18.0pt; mso-list:l20 level1 lfo6'><![if !supportLists]><span style='font-family:Symbol'>&middot;<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]><i>Description of an entity in the base system. </i><span style='font-style:normal'>Examples include data description, data location, process description, etc. These items will be in the lineage graph only if the base system reports them to the lineage system. For instance, in <span style='mso-field-code:"REF _Ref222045094 \\* MERGEFORMAT"'>Figure </span>3, the process node includes the description &#8220;Epidemic Projector, v3&#8221;.</span></p> <p class=ListParagraph style='margin-left:21.6pt;text-indent:-18.0pt; mso-list:l20 level1 lfo6'><![if !supportLists]><span style='font-family:Symbol'>&middot;<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]><i>Link to the underlying information. </i><span style='font-style:normal'>Base systems may keep more extensive information under their control, providing the lineage system only with a link, as in the Resource property of the nodes in <span style='mso-field-code:"REF _Ref222045094 \\* MERGEFORMAT"'>Figure </span>3<b>.</b></span><i><o:p></o:p></i></p> <p class=ListParagraph style='margin-left:21.6pt;text-indent:-18.0pt; mso-list:l20 level1 lfo6'><![if !supportLists]><span style='font-family:Symbol'>&middot;<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]><i>Description of a process invocation or creation of a dataset.</i><span style='font-style:normal'> For instance, the time started, time ended, who invoked it, whether data integrity was protected, etc. In the right-hand node record of <span style='mso-field-code:"REF _Ref222045094 \\* MERGEFORMAT"'>Figure </span>3, we can see that Analyst Smith invoked the process.</span><i><o:p></o:p></i></p> <p class=MsoNormal>This list is not intended to be exhaustive, but it gives lineage system security administrators an initial set of node and edge properties to address in formulating access policies. </p> <h1><a name="_Ref215384779"></a><a name="_Ref216066991"></a><a name="_Ref216498587"><span style='mso-bookmark:_Ref216066991'><span style='mso-bookmark:_Ref215384779'><![if !supportLists]>3. <![endif]>Access Control Extensions </span></span>for Lineage</a></h1> <p class=NormalPost-Header style='margin-bottom:0pt;margin-bottom:.0001pt'>We now discuss desirable extensions to prior work on access controls for lineage data: attribute-based access controls, modularization of concerns, and sharing of authority. </p> <p class=NormalPost-Header style='text-indent:12.25pt'>Section 3.1 shows the advantages of applying ABAC in lineage security. The next two subsections propose general purpose enhancements to ABAC formalisms and administrative processes, extensions that are particularly useful in settings such as lineage. In Section <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>REF _Ref222039192 \r <span style='mso-element:field-separator'></span><![endif]-->3.2<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->, we show how to handle with multiple concerns, while in Section <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>REF _Ref222124750 \r \h <span style='mso-element:field-separator'></span><![endif]-->3.3<!--[if gte mso 9]><xml> <w:data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F005200650066003200320032003100320034003700350030000000</w:data> </xml><![endif]--><!--[if supportFields]><span style='mso-element:field-end'></span><![endif]--> we deal with multiple stakeholders. Section 3.4 shows opportunities to build in lineage-specific definitions and defaults, without which the administrative burden would be prohibitive. </p> <h2><a name="_Ref216173402"><![if !supportLists]>3.1. <![endif]>Moving Toward Attribute-based Access Control</a></h2> <p class=MsoNormal style='text-indent:0pt'>In this section, we argue that ABAC, not RBAC, is the right basis for lineage security research, and give an overview of ABAC. Later sections exploit the flexibility of ABAC to propose additional capabilities. </p> <p class=NormalPost-Header style='margin-bottom:0pt;margin-bottom:.0001pt; text-indent:12.25pt'>Prior lineage security proposals used role-based access control (RBAC) <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Braun&lt;/Author&gt;&lt;Year&gt;2008&lt;/Year&gt;&lt;RecNum&gt;779&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;779&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;779&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Conference Proceedings&quot;&gt;10&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Uri Braun&lt;/author&gt;&lt;author&gt;Avaraham Shinnar&lt;/author&gt;&lt;author&gt;Margo Seltzer&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Securing Provenance&lt;/title&gt;&lt;secondary-title&gt;USENIX HotSec&lt;/secondary-title&gt;&lt;/titles&gt;&lt;dates&gt;&lt;year&gt;2008&lt;/year&gt;&lt;/dates&gt;&lt;urls&gt;&lt;/urls&gt;&lt;custom2&gt;2008&lt;/custom2&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;Cite&gt;&lt;Author&gt;Chebotko&lt;/Author&gt;&lt;Year&gt;2008&lt;/Year&gt;&lt;RecNum&gt;723&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;723&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;723&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Chebotko, Artem&lt;/author&gt;&lt;author&gt;Chang, Seunghan&lt;/author&gt;&lt;author&gt;Lu, Shiyong&lt;/author&gt;&lt;author&gt;Fotouhi, Farshad&lt;/author&gt;&lt;author&gt;Yang, Ping&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Scientific Workflow Provenance Querying with Security Views&lt;/title&gt;&lt;secondary-title&gt;WAIM&lt;/secondary-title&gt;&lt;/titles&gt;&lt;dates&gt;&lt;year&gt;2008&lt;/year&gt;&lt;/dates&gt;&lt;label&gt;chebotko08&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[8, 12]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->. Unfortunately, RBAC is known to suffer from serious scalability problems: As &#8220;policy becomes finer-grained and more attributes are involved, one gets a separate role for each combination of attribute values, making the user-to-role assignment and permission-to-role assignment tasks prohibitively expensive&#8221; <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Yuan&lt;/Author&gt;&lt;Year&gt;2005&lt;/Year&gt;&lt;RecNum&gt;784&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;784&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;784&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Conference Proceedings&quot;&gt;10&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;E. Yuan&lt;/author&gt;&lt;author&gt;J. Tong&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Attributed Based Access Control (ABAC) for Web Services&lt;/title&gt;&lt;secondary-title&gt;ICWS&lt;/secondary-title&gt;&lt;/titles&gt;&lt;pages&gt;561-569&lt;/pages&gt;&lt;dates&gt;&lt;year&gt;2005&lt;/year&gt;&lt;/dates&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[31]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->. If a new resource needs new policies, it needs a new set of roles, and users need to be provisioned into these. For example, a project management system may already know that Joe has joined a project team,<span style="mso-spacerun: yes">&nbsp; </span>that Mary is an MD, or that Task6 has been completed and roles in it are no longer valid, but this knowledge must be separately expressed and kept current as role assignments <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Rosenthal&lt;/Author&gt;&lt;Year&gt;2006&lt;/Year&gt;&lt;RecNum&gt;787&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;787&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;787&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Book Section&quot;&gt;5&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Arnon Rosenthal&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Scalable Access Policy Administration: Opinions and a Research Agenda &lt;/title&gt;&lt;secondary-title&gt;Security Management, Integrity, and Internal Control in Information Systems&lt;/secondary-title&gt;&lt;tertiary-title&gt;IFIP International Federation for Information Processing&lt;/tertiary-title&gt;&lt;/titles&gt;&lt;pages&gt;355-370&lt;/pages&gt;&lt;dates&gt;&lt;year&gt;2006&lt;/year&gt;&lt;/dates&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[26]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->.<span style="mso-spacerun: yes">&nbsp; </span>Finally, RBAC does not permit predicates that address resource or environment attributes, e.g. that a medical report is from Psychiatry, or that a request was submitted at 3AM. </p> <p class=MsoNormal>Attribute-based access control (ABAC) provides a more scalable alternative that satisfies these objections. Each relevant factor (e.g. project assignment, threat severity) is an attribute, which can be independently managed<a style='mso-footnote-id:ftn3' href="#_ftn3" name="_ftnref3" title=""><span class=MsoFootnoteReference><span style='font-family:Times'><span style='mso-special-character:footnote'><![if !supportFootnotes]>[3]<![endif]></span></span></span></a>. A predicate can reference as many different attributes as needed. Typically, attributes represent uncontroversial factual statements asserted by a trusted source, e.g. the current date, or that Analyst Smith&#8217;s assignment is BioDesk. One can also define computed attributes, e.g. <i>att<sub>new</sub></i><span style='font-family:Symbol;mso-char-type:symbol;mso-symbol-font-family:Symbol'><span style='mso-char-type:symbol;mso-symbol-font-family:Symbol'><i>@</i></span></span>&nbsp;<i>(att<sub>1</sub>&nbsp;</i><span style='font-family:Symbol;mso-char-type:symbol;mso-symbol-font-family:Symbol'><span style='mso-char-type:symbol;mso-symbol-font-family:Symbol'><i>&Uacute;</i></span></span><i>&nbsp;att<sub>2</sub>)&nbsp;</i><span style='font-family:Symbol;mso-char-type:symbol;mso-symbol-font-family:Symbol'><span style='mso-char-type:symbol;mso-symbol-font-family:Symbol'><i>&Ugrave;</i></span></span><i>(att<sub>3</sub>&gt; 2). </i></p> <p class=MsoNormal>For each protected item, an<i> </i><span style='font-style: normal'>administrator defines an </span><i>access predicate</i><span style='font-style:normal'>, which is formally a derived, unnamed attribute. The evaluator, or &#8220;policy decision point&#8221;, obtains attribute-value pairs for this request from an attribute service.</span><a style='mso-footnote-id: ftn4' href="#_ftn4" name="_ftnref4" title=""><span class=MsoFootnoteReference><span style='font-size:8.0pt;font-family:Times'><span style='mso-special-character: footnote'><![if !supportFootnotes]>[4]<![endif]></span></span></span></a><sup> </sup><span style="mso-spacerun: yes">&nbsp;</span>If the predicate returns True, access is permitted.</p> <p class=MsoNormal>The approach has several advantages. Since each attribute is managed independently, one supplies a linear amount of information (sum, not product, of the attribute extents). It is easy to incorporate multiple clauses. To reference a wider set of information, the predicate can reach into the existing information system. </p> <p class=MsoNormal style='text-indent:18.0pt'><a name="_Ref216505933">Administrators and system owners collaborate to manage the attribute set. Each attribute has a unique name, e.g. a URI. The unavoidable decentralization gives rise to the usual problems of semantic heterogeneity, and of motivating data providers across organizations </a><!--[if supportFields]><span style='mso-bookmark:_Ref216505933'></span><span style='mso-element:field-begin'></span><span style='mso-bookmark:_Ref216505933'><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Rosenthal&lt;/Author&gt;&lt;Year&gt;2004&lt;/Year&gt;&lt;RecNum&gt;410&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;410&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;410&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Rosenthal, Arnon&lt;/author&gt;&lt;author&gt;Seligman, Leonard J.&lt;/author&gt;&lt;author&gt;Renner, Scott&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;auth-address&gt;DBLP, http://dblp.uni-trier.de&lt;/auth-address&gt;&lt;titles&gt;&lt;title&gt;From semantic integration to semantics management: case studies and a way forward&lt;/title&gt;&lt;secondary-title&gt;SIGMOD Record&lt;/secondary-title&gt;&lt;/titles&gt;&lt;pages&gt;44-50&lt;/pages&gt;&lt;volume&gt;33&lt;/volume&gt;&lt;number&gt;4&lt;/number&gt;&lt;dates&gt;&lt;year&gt;2004&lt;/year&gt;&lt;/dates&gt;&lt;label&gt;DBLP:journals/sigmod/RosenthalSR04&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span></span><![endif]--><span style='mso-bookmark:_Ref216505933'>[27]</span><!--[if supportFields]><span style='mso-bookmark:_Ref216505933'></span><span style='mso-element:field-end'></span><![endif]--><span style='mso-bookmark:_Ref216505933'>.<span style="mso-spacerun: yes">&nbsp; </span>Administrators may define new attributes, and as in other flexible large scale data environments, they are allowed to invent or import attribute names in their own name spaces. </span></p> <p class=MsoNormal><span style='mso-bookmark:_Ref216505933'>Standards and commercial ABAC implementations are maturing, and we have personally observed several large government organizations exploring ABAC. They particularly like the fact that one can add new users simply by making their attributes available -- there is no need to &#8220;provision&#8221; them (i.e. to insert users into each relevant role). Additionally, new objects can be protected by defining predicates over existing attributes. XACML </span><!--[if supportFields]><span style='mso-bookmark:_Ref216505933'></span><span style='mso-element:field-begin'></span><span style='mso-bookmark:_Ref216505933'><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;RecNum&gt;788&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;788&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;788&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Web Page&quot;&gt;12&lt;/ref-type&gt;&lt;contributors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;XACML&lt;/title&gt;&lt;/titles&gt;&lt;dates&gt;&lt;/dates&gt;&lt;urls&gt;&lt;related-urls&gt;&lt;url&gt;http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=xacml&lt;/url&gt;&lt;/related-urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span></span><![endif]--><span style='mso-bookmark:_Ref216505933'>[2]</span><!--[if supportFields]><span style='mso-bookmark:_Ref216505933'></span><span style='mso-element:field-end'></span><![endif]--><span style='mso-bookmark:_Ref216505933'> is a standard language for passing predicates to enforcers. The SAML standard </span><!--[if supportFields]><span style='mso-bookmark:_Ref216505933'></span><span style='mso-element:field-begin'></span><span style='mso-bookmark:_Ref216505933'><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;RecNum&gt;789&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;789&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;789&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Web Page&quot;&gt;12&lt;/ref-type&gt;&lt;contributors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;SAML&lt;/title&gt;&lt;/titles&gt;&lt;dates&gt;&lt;/dates&gt;&lt;urls&gt;&lt;related-urls&gt;&lt;url&gt;http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=security&lt;/url&gt;&lt;/related-urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span></span><![endif]--><span style='mso-bookmark:_Ref216505933'>[1]</span><!--[if supportFields]><span style='mso-bookmark:_Ref216505933'></span><span style='mso-element:field-end'></span><![endif]--><span style='mso-bookmark:_Ref216505933'> allows assertions about attribute values and the trust in them to be passed around a distributed system. </span></p> <span style='mso-bookmark:_Ref216505933'></span> <h2 style='margin-bottom:0pt;margin-bottom:.0001pt'><a name="_Ref222039192"><![if !supportLists]>3.2. <![endif]>ABAC and Modular Concerns</a></h2> <p class=NormalPost-Header style='margin-bottom:0pt;margin-bottom:.0001pt'>ABAC has attracted wide interest in the security community. We enhance it here by tying it to explicit concerns. Even when all the concerns on an item are managed by a single person, the modularity and explicit links make it easier to edit or audit. </p> <p class=MsoNormal>We propose an extension of ABAC with explicit support for modular capture of concerns, i.e. named requirements that are linked to expression fragments that may be put into the access predicate. The administrator can delegate to other stakeholders the ability to define new attributes as well as access predicates. The administrator then writes (or, preferably, selects from a pre-defined library) a <i>combiner</i><span style='font-style: normal'> predicate. The most common combiners are likely to be </span><i>conjunction</i><span style='font-style:normal'>, which gives all authorized stakeholders a veto, </span><i>weighted voting</i><span style='font-style:normal'>, and </span><i>disjunctions</i><span style='font-style:normal'> representing alternate scenarios, as illustrated in the </span><i>Animal_Testing_Access</i><span style='font-style:normal'> predicate, but administrators may develop their own as needed. The advantage of this approach is increased modularity, traceability, and (optionally) delegation.</span></p> <p class=MsoNormal><span style="mso-spacerun: yes">&nbsp; </span>Each concern (e.g. to protect privacy or proprietary information such as the Epidemic Projector algorithm) can be assigned an attribute. When change is needed, the effort is modular:<span style="mso-spacerun: yes">&nbsp; </span>only one attribute requires inspection. Traceability is easy. </p> <p class=MsoNormal>While lineage access controls motivated us to add modular capture of stakeholder concerns to ABAC, we note that these capabilities have much broader applicability. For example, before a billing record can be released, a hospital must examine proprietary pricing concerns plus both the patient&#8217;s and the doctor&#8217;s privacy concerns. Similarly, before a research study can be released, one needs to see whether patients have given permission (or been de-identified), whether the researcher is willing to reveal his data to potential competitors, and whether the funding agency is satisfied. </p> <h2 style='margin-bottom:0pt;margin-bottom:.0001pt'><a name="_Ref222124750"><![if !supportLists]>3.3. <![endif]>ABAC and Sharing the Power</a></h2> <p class=MsoNormal>The example access predicate in Section 1 had contributions covering many different concerns, from many different people. One needs an authority structure to determine who can say how those contributions are to be put together, and then a process for those with proper authority to specify each needed combiner.</p> <p class=MsoNormal>Complex predicates like the one shown can arise in any arena, not just lineage. However, lineage is particularly prone to complex authority structures, because it often tracks information passing through many organizations, utilizing data and processes derived from disparate individuals and entities, and because a graph edge often connects independently owned processes. Other e-science stakeholders who may want a voice include suppliers of workflow templates, scientific funding agencies, and oversight agencies. </p> <p class=MsoNormal>Thus, it is rarely acceptable to appoint a lineage system administrator and give her full authority to decide what access controls to specify. Rather, the access predicate should reflect the different stakeholders&#8217; contributions, combined in a way specified by higher level stakeholders. Furthermore, when a stakeholder wants to change what she has specified, she should be able to change it directly, rather than sending an email to an administrator requesting a change. </p> <p class=MsoNormal>We outline here how to build on an ABAC system to achieve this flexibility, providing constructs and processes. The delegation operation is ordinary; the novelty is the process for using it. We begin with an overview, and then give an explicit algorithm.</p> <p class=MsoNormal>For uniformity, the access predicate for each protected item is treated as an attribute, and each attribute has a single authority.<span style="mso-spacerun: yes">&nbsp; </span>Normally the authority is an administrator; occasionally (e.g. for edges) it is the lineage system itself; for attributes that are statements of fact, it is an external source (e.g. an enterprise directory). </p> <p class=MsoNormal>The system helps attribute owners establish shared responsibility for their attribute, beginning with the top level access predicate and recursing downward. The owner of attribute A specifies a derivation for the value of A, by one of the following methods:</p> <p class=ListParagraph style='margin-left:21.6pt;text-indent:-18.0pt; mso-list:l12 level1 lfo57'><![if !supportLists]><span style='font-family:Symbol'>&middot;<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]>The owner provides a direct means (for example, one might look up a value in a database, or check membership in a traditional access control list), OR ELSE</p> <p class=ListParagraph style='margin-left:21.6pt;text-indent:-18.0pt; mso-list:l12 level1 lfo57'><![if !supportLists]><span style='font-family:Symbol'>&middot;<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]>The owner provides an expression tree to derive the attribute value:</p> <p class=ListParagraph style='margin-left:43.2pt;text-indent:-18.0pt; mso-list:l12 level2 lfo57'><![if !supportLists]><span style='font-family:"Courier New"'>o<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]>Pick a combiner function for the root. (One can create and register a new one as part of this step.)</p> <p class=ListParagraph style='margin-left:43.2pt;text-indent:-18.0pt; mso-list:l12 level2 lfo57'><![if !supportLists]><span style='font-family:"Courier New"'>o<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]>Bind some of the combiner&#8217;s input arguments to attributes that already exist. </p> <p class=ListParagraph style='margin-left:43.2pt;text-indent:-18.0pt; mso-list:l12 level2 lfo57'><![if !supportLists]><span style='font-family:"Courier New"'>o<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]>For each input argument that is not yet bound,</p> <p class=ListParagraph style='margin-left:64.8pt;text-indent:-18.0pt; mso-list:l12 level3 lfo57'><![if !supportLists]><span style='font-family:Wingdings'>&sect;<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]>Define a new attribute, with a unique URI (the definer is its owner, and must describe its meaning in text and bind it to input argument(s)), OR</p> <p class=ListParagraph style='margin-left:64.8pt;text-indent:-18.0pt; mso-list:l12 level3 lfo57'><![if !supportLists]><span style='font-family:Wingdings'>&sect;<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]>Optionally delegate ownership to somebody else.</p> <p class=ListParagraph style='margin-top:0pt;margin-right:0pt;margin-bottom: 6.0pt;margin-left:21.6pt;text-indent:-18.0pt;mso-list:l12 level1 lfo57'><![if !supportLists]><span style='font-family:Symbol'>&middot;<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]>Recursively, derive the value of newly created attributes, until it grounds in the first bulleted step.</p> <p class=MsoNormal>Delegation enables the work to be shared and to be done by the proper stakeholder (especially when different organizations are involved). </p> <h2><a name="_Ref222039268"><![if !supportLists]>3.4. <![endif]>Lineage Security over our ABAC Framework</a></h2> <p class=NormalPost-Header style='margin-bottom:0pt;margin-bottom:.0001pt'>As described above, fine-grained ABAC, complemented by tools to manage multiple stakeholder concerns, offers many benefits for lineage security. While the basic techniques apply to diverse applications (beyond lineage), we now consider special properties of lineage information that we can exploit to simplify access control policy administration. Ease of administration is critical; if administrators are forced to wade through long lists of attributes and stakeholders, the access control system is unusable. Therefore, we seek system defaults that predefine an initial set of protection concerns and their stakeholders. Additionally, pre-defined workflows present an opportunity for further reducing the security administration burden, and side agreements provide a convenient workaround for capabilities not built in.</p> <p class=MsoNormal>For ease of administration, different types of objects within a lineage graph should have pre-defined default stakeholders. For example, for <i>process nodes</i><span style='font-style:normal'>, the default stakeholders are the author (e.g., code developer) and the invoker of a specific execution. Meanwhile, for </span><i>data nodes</i><span style='font-style:normal'>, we must distinguish between external data and data generated by a process known to the lineage system. While stakeholder concerns (if any) must be explicitly asserted for external data, for other data the default stakeholders are those defined for the process that produced the data. Most often, the default will be the invoker of the process. Finally, for edges, the stakeholders are the union of the stakeholders of the source and destination nodes, although the concerns of stakeholders for each node are combined separately. The combined predicate from source node stakeholders represents what they are willing to reveal about the edge, as does the combined predicate of destination node stakeholders. The concerns of both nodes&#8217; stakeholders are then reconciled to determine whether to reveal the edge. The default is a veto &#8211; access to the edge is only granted if both sets of stakeholders allow it. </span></p> <p class=MsoNormal>Up to this point, we have discussed ad hoc executions. However, a large body of lineage research concerns routine computations in which a pre-defined workflow is run many times <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE <span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE.DATA <![if gte mso 9]><xml> <w:data>3C456E644E6F74653E3C436974653E3C417574686F723E4F696E6E3C2F417574686F723E3C596561723E323030363C2F596561723E3C5265634E756D3E3537373C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3537373C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3537373C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E4F696E6E2C20546F6D3C2F617574686F723E3C617574686F723E477265656E776F6F642C204D61726B3C2F617574686F723E3C617574686F723E41646469732C204D6174746865773C2F617574686F723E3C617574686F723E416C7064656D69722C204D2E204E6564696D3C2F617574686F723E3C617574686F723E4665727269732C204A757374696E3C2F617574686F723E3C617574686F723E476C6F7665722C204B6576696E3C2F617574686F723E3C617574686F723E476F626C652C204361726F6C653C2F617574686F723E3C617574686F723E476F64657269732C20416E746F6F6E3C2F617574686F723E3C617574686F723E48756C6C2C2044756E63616E3C2F617574686F723E3C617574686F723E4D617276696E2C2044617272656E3C2F617574686F723E3C617574686F723E4C692C2050657465723C2F617574686F723E3C617574686F723E4C6F72642C205068696C6C69703C2F617574686F723E3C617574686F723E506F636F636B2C204D61747468657720522E3C2F617574686F723E3C617574686F723E53656E6765722C204D617274696E3C2F617574686F723E3C617574686F723E53746576656E732C20526F626572743C2F617574686F723E3C617574686F723E57697061742C20416E696C3C2F617574686F723E3C617574686F723E57726F652C2043687269733C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E54617665726E613A206C6573736F6E7320696E206372656174696E67206120776F726B666C6F7720656E7669726F6E6D656E7420666F7220746865206C69666520736369656E6365733A2052657365617263682041727469636C65733C2F7469746C653E3C7365636F6E646172792D7469746C653E436F6E637572722E20436F6D7075742E203A2050726163742E2045787065722E3C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E313036372D313130303C2F70616765733E3C766F6C756D653E31383C2F766F6C756D653E3C6E756D6265723E31303C2F6E756D6265723E3C64617465733E3C796561723E323030363C2F796561723E3C2F64617465733E3C6C6162656C3E74617665726E613C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E43616C6C6168616E3C2F417574686F723E3C596561723E323030363C2F596561723E3C5265634E756D3E3538383C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3538383C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3538383C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E43616C6C6168616E2C2053746576656E20502E3C2F617574686F723E3C617574686F723E4672656972652C204A756C69616E613C2F617574686F723E3C617574686F723E53616E746F732C20456D616E75656C653C2F617574686F723E3C617574686F723E53636865696465676765722C204361726C6F7320452E3C2F617574686F723E3C617574686F723E566F2C20436CC3A17564696F20542E2053696C7661616E642048757920542E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E566973547261696C733A2056697375616C697A6174696F6E206D656574732044617461204D616E6167656D656E743C2F7469746C653E3C7365636F6E646172792D7469746C653E5349474D4F443C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E3734352D3734373C2F70616765733E3C64617465733E3C796561723E323030363C2F796561723E3C2F64617465733E3C6C6162656C3E66726569726530363C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E4D6F726561753C2F417574686F723E3C596561723E323030383C2F596561723E3C5265634E756D3E3631303C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3631303C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3631303C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E4D6F726561752C204C75633C2F617574686F723E3C617574686F723E4C7564C3A473636865722C204265727472616D3C2F617574686F723E3C617574686F723E416C74696E7461732C20496C6B61793C2F617574686F723E3C617574686F723E42617267612C20526F67657220532E3C2F617574686F723E3C617574686F723E426F776572732C20536861776E3C2F617574686F723E3C617574686F723E43616C6C6168616E2C2053746576656E3C2F617574686F723E3C617574686F723E4A522E2C2047656F726765204368696E3C2F617574686F723E3C617574686F723E436C6966666F72642C2042656E3C2F617574686F723E3C617574686F723E436F68656E2C20536869726C65793C2F617574686F723E3C617574686F723E436F68656E2D426F756C616B69612C2053617261683C2F617574686F723E3C617574686F723E4461766964736F6E2C20537573616E3C2F617574686F723E3C617574686F723E4465656C6D616E2C204577613C2F617574686F723E3C617574686F723E44696769616D7069657472692C204C756369616E6F3C2F617574686F723E3C617574686F723E466F737465722C2049616E3C2F617574686F723E3C617574686F723E4672656972652C204A756C69616E613C2F617574686F723E3C617574686F723E467265772C204A616D65733C2F617574686F723E3C617574686F723E46757472656C6C652C204A6F653C2F617574686F723E3C617574686F723E476962736F6E2C20546172613C2F617574686F723E3C617574686F723E47696C2C20596F6C616E64613C2F617574686F723E3C617574686F723E476F626C652C204361726F6C653C2F617574686F723E3C617574686F723E476F6C6265636B2C204A656E6E696665723C2F617574686F723E3C617574686F723E47726F74682C205061756C3C2F617574686F723E3C617574686F723E486F6C6C616E642C20446176696420412E3C2F617574686F723E3C617574686F723E4A69616E672C205368656E673C2F617574686F723E3C617574686F723E4B696D2C204A696869653C2F617574686F723E3C617574686F723E4B6F6F702C2044617669643C2F617574686F723E3C617574686F723E4B72656E656B2C20416C65733C2F617574686F723E3C617574686F723E4D635068696C6C6970732C2054696D6F7468793C2F617574686F723E3C617574686F723E4D656874612C2047617572616E673C2F617574686F723E3C617574686F723E4D696C65732C2053696D6F6E3C2F617574686F723E3C617574686F723E4D65747A6765722C20446F6D696E69633C2F617574686F723E3C617574686F723E4D756E726F652C2053746576653C2F617574686F723E3C617574686F723E4D796572732C204A696D3C2F617574686F723E3C617574686F723E506C616C652C20426574683C2F617574686F723E3C617574686F723E506F64686F72737A6B692C204E6F72626572743C2F617574686F723E3C617574686F723E5261746E616B61722C20566172756E3C2F617574686F723E3C617574686F723E53616E746F732C20456D616E75656C653C2F617574686F723E3C617574686F723E53636865696465676765722C204361726C6F733C2F617574686F723E3C617574686F723E536368756368617264742C204B6172656E3C2F617574686F723E3C617574686F723E53656C747A65722C204D6172676F3C2F617574686F723E3C617574686F723E53696D6D68616E2C20596F67657368204C2E3C2F617574686F723E3C617574686F723E53696C76612C20436C617564696F3C2F617574686F723E3C617574686F723E536C617567687465722C2050657465723C2F617574686F723E3C617574686F723E5374657068616E2C20457269633C2F617574686F723E3C617574686F723E53746576656E732C20526F626572743C2F617574686F723E3C617574686F723E547572692C2044616E69656C653C2F617574686F723E3C617574686F723E566F2C204875793C2F617574686F723E3C617574686F723E57696C64652C204D696B653C2F617574686F723E3C617574686F723E5A68616F2C204A756E3C2F617574686F723E3C617574686F723E5A68616F2C20596F6E673C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E5370656369616C2049737375653A205468652046697273742050726F76656E616E6365204368616C6C656E67653C2F7469746C653E3C7365636F6E646172792D7469746C653E436F6E63757272656E637920616E6420436F6D7075746174696F6E3A20507261637469636520616E6420457870657269656E63653C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E3430392D3431383C2F70616765733E3C766F6C756D653E32303C2F766F6C756D653E3C64617465733E3C796561723E323030383C2F796561723E3C2F64617465733E3C6C6162656C3E6D6F7265617530383C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C2F456E644E6F74653E</w:data> </xml><![endif]><span style='mso-element:field-end'></span><span style='mso-element:field-separator'></span><![endif]-->[10, 23, 25]<!--[if gte mso 9]><xml> <w:data>3C456E644E6F74653E3C436974653E3C417574686F723E4F696E6E3C2F417574686F723E3C596561723E323030363C2F596561723E3C5265634E756D3E3537373C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3537373C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3537373C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E4F696E6E2C20546F6D3C2F617574686F723E3C617574686F723E477265656E776F6F642C204D61726B3C2F617574686F723E3C617574686F723E41646469732C204D6174746865773C2F617574686F723E3C617574686F723E416C7064656D69722C204D2E204E6564696D3C2F617574686F723E3C617574686F723E4665727269732C204A757374696E3C2F617574686F723E3C617574686F723E476C6F7665722C204B6576696E3C2F617574686F723E3C617574686F723E476F626C652C204361726F6C653C2F617574686F723E3C617574686F723E476F64657269732C20416E746F6F6E3C2F617574686F723E3C617574686F723E48756C6C2C2044756E63616E3C2F617574686F723E3C617574686F723E4D617276696E2C2044617272656E3C2F617574686F723E3C617574686F723E4C692C2050657465723C2F617574686F723E3C617574686F723E4C6F72642C205068696C6C69703C2F617574686F723E3C617574686F723E506F636F636B2C204D61747468657720522E3C2F617574686F723E3C617574686F723E53656E6765722C204D617274696E3C2F617574686F723E3C617574686F723E53746576656E732C20526F626572743C2F617574686F723E3C617574686F723E57697061742C20416E696C3C2F617574686F723E3C617574686F723E57726F652C2043687269733C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E54617665726E613A206C6573736F6E7320696E206372656174696E67206120776F726B666C6F7720656E7669726F6E6D656E7420666F7220746865206C69666520736369656E6365733A2052657365617263682041727469636C65733C2F7469746C653E3C7365636F6E646172792D7469746C653E436F6E637572722E20436F6D7075742E203A2050726163742E2045787065722E3C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E313036372D313130303C2F70616765733E3C766F6C756D653E31383C2F766F6C756D653E3C6E756D6265723E31303C2F6E756D6265723E3C64617465733E3C796561723E323030363C2F796561723E3C2F64617465733E3C6C6162656C3E74617665726E613C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E43616C6C6168616E3C2F417574686F723E3C596561723E323030363C2F596561723E3C5265634E756D3E3538383C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3538383C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3538383C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E43616C6C6168616E2C2053746576656E20502E3C2F617574686F723E3C617574686F723E4672656972652C204A756C69616E613C2F617574686F723E3C617574686F723E53616E746F732C20456D616E75656C653C2F617574686F723E3C617574686F723E53636865696465676765722C204361726C6F7320452E3C2F617574686F723E3C617574686F723E566F2C20436CC3A17564696F20542E2053696C7661616E642048757920542E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E566973547261696C733A2056697375616C697A6174696F6E206D656574732044617461204D616E6167656D656E743C2F7469746C653E3C7365636F6E646172792D7469746C653E5349474D4F443C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E3734352D3734373C2F70616765733E3C64617465733E3C796561723E323030363C2F796561723E3C2F64617465733E3C6C6162656C3E66726569726530363C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E4D6F726561753C2F417574686F723E3C596561723E323030383C2F596561723E3C5265634E756D3E3631303C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3631303C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3631303C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E4D6F726561752C204C75633C2F617574686F723E3C617574686F723E4C7564C3A473636865722C204265727472616D3C2F617574686F723E3C617574686F723E416C74696E7461732C20496C6B61793C2F617574686F723E3C617574686F723E42617267612C20526F67657220532E3C2F617574686F723E3C617574686F723E426F776572732C20536861776E3C2F617574686F723E3C617574686F723E43616C6C6168616E2C2053746576656E3C2F617574686F723E3C617574686F723E4A522E2C2047656F726765204368696E3C2F617574686F723E3C617574686F723E436C6966666F72642C2042656E3C2F617574686F723E3C617574686F723E436F68656E2C20536869726C65793C2F617574686F723E3C617574686F723E436F68656E2D426F756C616B69612C2053617261683C2F617574686F723E3C617574686F723E4461766964736F6E2C20537573616E3C2F617574686F723E3C617574686F723E4465656C6D616E2C204577613C2F617574686F723E3C617574686F723E44696769616D7069657472692C204C756369616E6F3C2F617574686F723E3C617574686F723E466F737465722C2049616E3C2F617574686F723E3C617574686F723E4672656972652C204A756C69616E613C2F617574686F723E3C617574686F723E467265772C204A616D65733C2F617574686F723E3C617574686F723E46757472656C6C652C204A6F653C2F617574686F723E3C617574686F723E476962736F6E2C20546172613C2F617574686F723E3C617574686F723E47696C2C20596F6C616E64613C2F617574686F723E3C617574686F723E476F626C652C204361726F6C653C2F617574686F723E3C617574686F723E476F6C6265636B2C204A656E6E696665723C2F617574686F723E3C617574686F723E47726F74682C205061756C3C2F617574686F723E3C617574686F723E486F6C6C616E642C20446176696420412E3C2F617574686F723E3C617574686F723E4A69616E672C205368656E673C2F617574686F723E3C617574686F723E4B696D2C204A696869653C2F617574686F723E3C617574686F723E4B6F6F702C2044617669643C2F617574686F723E3C617574686F723E4B72656E656B2C20416C65733C2F617574686F723E3C617574686F723E4D635068696C6C6970732C2054696D6F7468793C2F617574686F723E3C617574686F723E4D656874612C2047617572616E673C2F617574686F723E3C617574686F723E4D696C65732C2053696D6F6E3C2F617574686F723E3C617574686F723E4D65747A6765722C20446F6D696E69633C2F617574686F723E3C617574686F723E4D756E726F652C2053746576653C2F617574686F723E3C617574686F723E4D796572732C204A696D3C2F617574686F723E3C617574686F723E506C616C652C20426574683C2F617574686F723E3C617574686F723E506F64686F72737A6B692C204E6F72626572743C2F617574686F723E3C617574686F723E5261746E616B61722C20566172756E3C2F617574686F723E3C617574686F723E53616E746F732C20456D616E75656C653C2F617574686F723E3C617574686F723E53636865696465676765722C204361726C6F733C2F617574686F723E3C617574686F723E536368756368617264742C204B6172656E3C2F617574686F723E3C617574686F723E53656C747A65722C204D6172676F3C2F617574686F723E3C617574686F723E53696D6D68616E2C20596F67657368204C2E3C2F617574686F723E3C617574686F723E53696C76612C20436C617564696F3C2F617574686F723E3C617574686F723E536C617567687465722C2050657465723C2F617574686F723E3C617574686F723E5374657068616E2C20457269633C2F617574686F723E3C617574686F723E53746576656E732C20526F626572743C2F617574686F723E3C617574686F723E547572692C2044616E69656C653C2F617574686F723E3C617574686F723E566F2C204875793C2F617574686F723E3C617574686F723E57696C64652C204D696B653C2F617574686F723E3C617574686F723E5A68616F2C204A756E3C2F617574686F723E3C617574686F723E5A68616F2C20596F6E673C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E5370656369616C2049737375653A205468652046697273742050726F76656E616E6365204368616C6C656E67653C2F7469746C653E3C7365636F6E646172792D7469746C653E436F6E63757272656E637920616E6420436F6D7075746174696F6E3A20507261637469636520616E6420457870657269656E63653C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E3430392D3431383C2F70616765733E3C766F6C756D653E32303C2F766F6C756D653E3C64617465733E3C796561723E323030383C2F796561723E3C2F64617465733E3C6C6162656C3E6D6F7265617530383C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C2F456E644E6F74653E</w:data> </xml><![endif]--><!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->.<span style="mso-spacerun: yes">&nbsp; </span>The lineage system can automatically generate much of the information needed to describe the resulting history to the lineage store. The workflow creator is allowed to express access control specifications on nodes or properties, and is automatically made an additional stakeholder whose concerns will be combined with those of others. Also, if a (process or data) object is to be used in many instances of the workflow, the item&#8217;s policy can be propagated automatically into the instantiations. Much of this was done in <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Chebotko&lt;/Author&gt;&lt;Year&gt;2008&lt;/Year&gt;&lt;RecNum&gt;723&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;723&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;723&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Chebotko, Artem&lt;/author&gt;&lt;author&gt;Chang, Seunghan&lt;/author&gt;&lt;author&gt;Lu, Shiyong&lt;/author&gt;&lt;author&gt;Fotouhi, Farshad&lt;/author&gt;&lt;author&gt;Yang, Ping&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Scientific Workflow Provenance Querying with Security Views&lt;/title&gt;&lt;secondary-title&gt;WAIM&lt;/secondary-title&gt;&lt;/titles&gt;&lt;dates&gt;&lt;year&gt;2008&lt;/year&gt;&lt;/dates&gt;&lt;label&gt;chebotko08&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[12]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->. We suggest going farther by propagating access predicates on the properties, and coping with mixed histories (partly <i>ad hoc </i><span style='font-style:normal'>and partly derived from workflows). </span></p> <p class=MsoNormal>To keep the lineage system simple, we did not attempt to provide all possible constructs, nor to define all possible classes of Concern or Stakeholder. One omission was sticky policies (a sort of mandatory access control that goes from a node to all nodes downstream, requiring that the certain clauses be attached to policies on the downstream objects). For example a GNU public license requires that derived products be freely shared, if deployed as a single package. Additionally, we did not automatically build in a veto right for certain<span style="mso-spacerun: yes">&nbsp; </span>stakeholders, e.g. a company which may hold proprietary rights to all data produced by its employees, or a funding agency which may insist that all grantees reveal how they produced their results. </p> <p class=MsoNormal>We know of no ABAC constructs for this. Such situations can be handled by side agreements among administrators, e.g. agreeing to insert a veto or to extend access to organizations that maintain a non-disclosure agreement. In addition to keeping the lineage system of manageable size, there is another reason not to build constructs for all these cases into the lineage model. Many side agreements may need to cover the base system as well as lineage, and there is little chance of extending the models in all relevant base systems. </p> <h1><a name="_Ref216498631"><![if !supportLists]>4. <![endif]>Related Work</a></h1> <h2><![if !supportLists]>4.1. <![endif]>Lineage Systems</h2> <p class=NormalPost-Header style='margin-bottom:0pt;margin-bottom:.0001pt'>Lineage has become an active research area. Some systems collect lineage generated from executing pre-defined, explicit workflows <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE <span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE.DATA <![if gte mso 9]><xml> <w:data>3C456E644E6F74653E3C436974653E3C417574686F723E4D6F726561753C2F417574686F723E3C596561723E323030383C2F596561723E3C5265634E756D3E3631303C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3631303C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3631303C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E4D6F726561752C204C75633C2F617574686F723E3C617574686F723E4C7564C3A473636865722C204265727472616D3C2F617574686F723E3C617574686F723E416C74696E7461732C20496C6B61793C2F617574686F723E3C617574686F723E42617267612C20526F67657220532E3C2F617574686F723E3C617574686F723E426F776572732C20536861776E3C2F617574686F723E3C617574686F723E43616C6C6168616E2C2053746576656E3C2F617574686F723E3C617574686F723E4A522E2C2047656F726765204368696E3C2F617574686F723E3C617574686F723E436C6966666F72642C2042656E3C2F617574686F723E3C617574686F723E436F68656E2C20536869726C65793C2F617574686F723E3C617574686F723E436F68656E2D426F756C616B69612C2053617261683C2F617574686F723E3C617574686F723E4461766964736F6E2C20537573616E3C2F617574686F723E3C617574686F723E4465656C6D616E2C204577613C2F617574686F723E3C617574686F723E44696769616D7069657472692C204C756369616E6F3C2F617574686F723E3C617574686F723E466F737465722C2049616E3C2F617574686F723E3C617574686F723E4672656972652C204A756C69616E613C2F617574686F723E3C617574686F723E467265772C204A616D65733C2F617574686F723E3C617574686F723E46757472656C6C652C204A6F653C2F617574686F723E3C617574686F723E476962736F6E2C20546172613C2F617574686F723E3C617574686F723E47696C2C20596F6C616E64613C2F617574686F723E3C617574686F723E476F626C652C204361726F6C653C2F617574686F723E3C617574686F723E476F6C6265636B2C204A656E6E696665723C2F617574686F723E3C617574686F723E47726F74682C205061756C3C2F617574686F723E3C617574686F723E486F6C6C616E642C20446176696420412E3C2F617574686F723E3C617574686F723E4A69616E672C205368656E673C2F617574686F723E3C617574686F723E4B696D2C204A696869653C2F617574686F723E3C617574686F723E4B6F6F702C2044617669643C2F617574686F723E3C617574686F723E4B72656E656B2C20416C65733C2F617574686F723E3C617574686F723E4D635068696C6C6970732C2054696D6F7468793C2F617574686F723E3C617574686F723E4D656874612C2047617572616E673C2F617574686F723E3C617574686F723E4D696C65732C2053696D6F6E3C2F617574686F723E3C617574686F723E4D65747A6765722C20446F6D696E69633C2F617574686F723E3C617574686F723E4D756E726F652C2053746576653C2F617574686F723E3C617574686F723E4D796572732C204A696D3C2F617574686F723E3C617574686F723E506C616C652C20426574683C2F617574686F723E3C617574686F723E506F64686F72737A6B692C204E6F72626572743C2F617574686F723E3C617574686F723E5261746E616B61722C20566172756E3C2F617574686F723E3C617574686F723E53616E746F732C20456D616E75656C653C2F617574686F723E3C617574686F723E53636865696465676765722C204361726C6F733C2F617574686F723E3C617574686F723E536368756368617264742C204B6172656E3C2F617574686F723E3C617574686F723E53656C747A65722C204D6172676F3C2F617574686F723E3C617574686F723E53696D6D68616E2C20596F67657368204C2E3C2F617574686F723E3C617574686F723E53696C76612C20436C617564696F3C2F617574686F723E3C617574686F723E536C617567687465722C2050657465723C2F617574686F723E3C617574686F723E5374657068616E2C20457269633C2F617574686F723E3C617574686F723E53746576656E732C20526F626572743C2F617574686F723E3C617574686F723E547572692C2044616E69656C653C2F617574686F723E3C617574686F723E566F2C204875793C2F617574686F723E3C617574686F723E57696C64652C204D696B653C2F617574686F723E3C617574686F723E5A68616F2C204A756E3C2F617574686F723E3C617574686F723E5A68616F2C20596F6E673C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E5370656369616C2049737375653A205468652046697273742050726F76656E616E6365204368616C6C656E67653C2F7469746C653E3C7365636F6E646172792D7469746C653E436F6E63757272656E637920616E6420436F6D7075746174696F6E3A20507261637469636520616E6420457870657269656E63653C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E3430392D3431383C2F70616765733E3C766F6C756D653E32303C2F766F6C756D653E3C64617465733E3C796561723E323030383C2F796561723E3C2F64617465733E3C6C6162656C3E6D6F7265617530383C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E43616C6C6168616E3C2F417574686F723E3C596561723E323030363C2F596561723E3C5265634E756D3E3538383C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3538383C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3538383C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E43616C6C6168616E2C2053746576656E20502E3C2F617574686F723E3C617574686F723E4672656972652C204A756C69616E613C2F617574686F723E3C617574686F723E53616E746F732C20456D616E75656C653C2F617574686F723E3C617574686F723E53636865696465676765722C204361726C6F7320452E3C2F617574686F723E3C617574686F723E566F2C20436CC3A17564696F20542E2053696C7661616E642048757920542E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E566973547261696C733A2056697375616C697A6174696F6E206D656574732044617461204D616E6167656D656E743C2F7469746C653E3C7365636F6E646172792D7469746C653E5349474D4F443C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E3734352D3734373C2F70616765733E3C64617465733E3C796561723E323030363C2F796561723E3C2F64617465733E3C6C6162656C3E66726569726530363C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E4461766964736F6E3C2F417574686F723E3C596561723E323030373C2F596561723E3C5265634E756D3E3539333C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3539333C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3539333C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E4461766964736F6E2C20537573616E3C2F617574686F723E3C617574686F723E436F68656E2D426F756C616B69612C2053617261683C2F617574686F723E3C617574686F723E4579616C2C20416E61743C2F617574686F723E3C617574686F723E4C75646173636865722C204265727472616D3C2F617574686F723E3C617574686F723E4D635068696C6C6970732C2054696D6F7468793C2F617574686F723E3C617574686F723E426F776572732C20536861776E3C2F617574686F723E3C617574686F723E4672656972652C204A756C69616E613C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E50726F76656E616E636520696E20536369656E746966696320576F726B666C6F772053797374656D733C2F7469746C653E3C7365636F6E646172792D7469746C653E49454545204461746120456E67696E656572696E672042756C6C6574696E3C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E34342D35303C2F70616765733E3C766F6C756D653E33323C2F766F6C756D653E3C6E756D6265723E343C2F6E756D6265723E3C64617465733E3C796561723E323030373C2F796561723E3C2F64617465733E3C6C6162656C3E6461766964736F6E30373C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E4F696E6E3C2F417574686F723E3C596561723E323030363C2F596561723E3C5265634E756D3E3537373C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3537373C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3537373C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E4F696E6E2C20546F6D3C2F617574686F723E3C617574686F723E477265656E776F6F642C204D61726B3C2F617574686F723E3C617574686F723E41646469732C204D6174746865773C2F617574686F723E3C617574686F723E416C7064656D69722C204D2E204E6564696D3C2F617574686F723E3C617574686F723E4665727269732C204A757374696E3C2F617574686F723E3C617574686F723E476C6F7665722C204B6576696E3C2F617574686F723E3C617574686F723E476F626C652C204361726F6C653C2F617574686F723E3C617574686F723E476F64657269732C20416E746F6F6E3C2F617574686F723E3C617574686F723E48756C6C2C2044756E63616E3C2F617574686F723E3C617574686F723E4D617276696E2C2044617272656E3C2F617574686F723E3C617574686F723E4C692C2050657465723C2F617574686F723E3C617574686F723E4C6F72642C205068696C6C69703C2F617574686F723E3C617574686F723E506F636F636B2C204D61747468657720522E3C2F617574686F723E3C617574686F723E53656E6765722C204D617274696E3C2F617574686F723E3C617574686F723E53746576656E732C20526F626572743C2F617574686F723E3C617574686F723E57697061742C20416E696C3C2F617574686F723E3C617574686F723E57726F652C2043687269733C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E54617665726E613A206C6573736F6E7320696E206372656174696E67206120776F726B666C6F7720656E7669726F6E6D656E7420666F7220746865206C69666520736369656E6365733A2052657365617263682041727469636C65733C2F7469746C653E3C7365636F6E646172792D7469746C653E436F6E637572722E20436F6D7075742E203A2050726163742E2045787065722E3C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E313036372D313130303C2F70616765733E3C766F6C756D653E31383C2F766F6C756D653E3C6E756D6265723E31303C2F6E756D6265723E3C64617465733E3C796561723E323030363C2F796561723E3C2F64617465733E3C6C6162656C3E74617665726E613C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C2F456E644E6F74653E</w:data> </xml><![endif]><span style='mso-element:field-end'></span><span style='mso-element:field-separator'></span><![endif]-->[10, 15, 23, 25]<!--[if gte mso 9]><xml> <w:data>3C456E644E6F74653E3C436974653E3C417574686F723E4D6F726561753C2F417574686F723E3C596561723E323030383C2F596561723E3C5265634E756D3E3631303C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3631303C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3631303C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E4D6F726561752C204C75633C2F617574686F723E3C617574686F723E4C7564C3A473636865722C204265727472616D3C2F617574686F723E3C617574686F723E416C74696E7461732C20496C6B61793C2F617574686F723E3C617574686F723E42617267612C20526F67657220532E3C2F617574686F723E3C617574686F723E426F776572732C20536861776E3C2F617574686F723E3C617574686F723E43616C6C6168616E2C2053746576656E3C2F617574686F723E3C617574686F723E4A522E2C2047656F726765204368696E3C2F617574686F723E3C617574686F723E436C6966666F72642C2042656E3C2F617574686F723E3C617574686F723E436F68656E2C20536869726C65793C2F617574686F723E3C617574686F723E436F68656E2D426F756C616B69612C2053617261683C2F617574686F723E3C617574686F723E4461766964736F6E2C20537573616E3C2F617574686F723E3C617574686F723E4465656C6D616E2C204577613C2F617574686F723E3C617574686F723E44696769616D7069657472692C204C756369616E6F3C2F617574686F723E3C617574686F723E466F737465722C2049616E3C2F617574686F723E3C617574686F723E4672656972652C204A756C69616E613C2F617574686F723E3C617574686F723E467265772C204A616D65733C2F617574686F723E3C617574686F723E46757472656C6C652C204A6F653C2F617574686F723E3C617574686F723E476962736F6E2C20546172613C2F617574686F723E3C617574686F723E47696C2C20596F6C616E64613C2F617574686F723E3C617574686F723E476F626C652C204361726F6C653C2F617574686F723E3C617574686F723E476F6C6265636B2C204A656E6E696665723C2F617574686F723E3C617574686F723E47726F74682C205061756C3C2F617574686F723E3C617574686F723E486F6C6C616E642C20446176696420412E3C2F617574686F723E3C617574686F723E4A69616E672C205368656E673C2F617574686F723E3C617574686F723E4B696D2C204A696869653C2F617574686F723E3C617574686F723E4B6F6F702C2044617669643C2F617574686F723E3C617574686F723E4B72656E656B2C20416C65733C2F617574686F723E3C617574686F723E4D635068696C6C6970732C2054696D6F7468793C2F617574686F723E3C617574686F723E4D656874612C2047617572616E673C2F617574686F723E3C617574686F723E4D696C65732C2053696D6F6E3C2F617574686F723E3C617574686F723E4D65747A6765722C20446F6D696E69633C2F617574686F723E3C617574686F723E4D756E726F652C2053746576653C2F617574686F723E3C617574686F723E4D796572732C204A696D3C2F617574686F723E3C617574686F723E506C616C652C20426574683C2F617574686F723E3C617574686F723E506F64686F72737A6B692C204E6F72626572743C2F617574686F723E3C617574686F723E5261746E616B61722C20566172756E3C2F617574686F723E3C617574686F723E53616E746F732C20456D616E75656C653C2F617574686F723E3C617574686F723E53636865696465676765722C204361726C6F733C2F617574686F723E3C617574686F723E536368756368617264742C204B6172656E3C2F617574686F723E3C617574686F723E53656C747A65722C204D6172676F3C2F617574686F723E3C617574686F723E53696D6D68616E2C20596F67657368204C2E3C2F617574686F723E3C617574686F723E53696C76612C20436C617564696F3C2F617574686F723E3C617574686F723E536C617567687465722C2050657465723C2F617574686F723E3C617574686F723E5374657068616E2C20457269633C2F617574686F723E3C617574686F723E53746576656E732C20526F626572743C2F617574686F723E3C617574686F723E547572692C2044616E69656C653C2F617574686F723E3C617574686F723E566F2C204875793C2F617574686F723E3C617574686F723E57696C64652C204D696B653C2F617574686F723E3C617574686F723E5A68616F2C204A756E3C2F617574686F723E3C617574686F723E5A68616F2C20596F6E673C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E5370656369616C2049737375653A205468652046697273742050726F76656E616E6365204368616C6C656E67653C2F7469746C653E3C7365636F6E646172792D7469746C653E436F6E63757272656E637920616E6420436F6D7075746174696F6E3A20507261637469636520616E6420457870657269656E63653C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E3430392D3431383C2F70616765733E3C766F6C756D653E32303C2F766F6C756D653E3C64617465733E3C796561723E323030383C2F796561723E3C2F64617465733E3C6C6162656C3E6D6F7265617530383C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E43616C6C6168616E3C2F417574686F723E3C596561723E323030363C2F596561723E3C5265634E756D3E3538383C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3538383C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3538383C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E43616C6C6168616E2C2053746576656E20502E3C2F617574686F723E3C617574686F723E4672656972652C204A756C69616E613C2F617574686F723E3C617574686F723E53616E746F732C20456D616E75656C653C2F617574686F723E3C617574686F723E53636865696465676765722C204361726C6F7320452E3C2F617574686F723E3C617574686F723E566F2C20436CC3A17564696F20542E2053696C7661616E642048757920542E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E566973547261696C733A2056697375616C697A6174696F6E206D656574732044617461204D616E6167656D656E743C2F7469746C653E3C7365636F6E646172792D7469746C653E5349474D4F443C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E3734352D3734373C2F70616765733E3C64617465733E3C796561723E323030363C2F796561723E3C2F64617465733E3C6C6162656C3E66726569726530363C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E4461766964736F6E3C2F417574686F723E3C596561723E323030373C2F596561723E3C5265634E756D3E3539333C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3539333C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3539333C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E4461766964736F6E2C20537573616E3C2F617574686F723E3C617574686F723E436F68656E2D426F756C616B69612C2053617261683C2F617574686F723E3C617574686F723E4579616C2C20416E61743C2F617574686F723E3C617574686F723E4C75646173636865722C204265727472616D3C2F617574686F723E3C617574686F723E4D635068696C6C6970732C2054696D6F7468793C2F617574686F723E3C617574686F723E426F776572732C20536861776E3C2F617574686F723E3C617574686F723E4672656972652C204A756C69616E613C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E50726F76656E616E636520696E20536369656E746966696320576F726B666C6F772053797374656D733C2F7469746C653E3C7365636F6E646172792D7469746C653E49454545204461746120456E67696E656572696E672042756C6C6574696E3C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E34342D35303C2F70616765733E3C766F6C756D653E33323C2F766F6C756D653E3C6E756D6265723E343C2F6E756D6265723E3C64617465733E3C796561723E323030373C2F796561723E3C2F64617465733E3C6C6162656C3E6461766964736F6E30373C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E4F696E6E3C2F417574686F723E3C596561723E323030363C2F596561723E3C5265634E756D3E3537373C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3537373C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3537373C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E4F696E6E2C20546F6D3C2F617574686F723E3C617574686F723E477265656E776F6F642C204D61726B3C2F617574686F723E3C617574686F723E41646469732C204D6174746865773C2F617574686F723E3C617574686F723E416C7064656D69722C204D2E204E6564696D3C2F617574686F723E3C617574686F723E4665727269732C204A757374696E3C2F617574686F723E3C617574686F723E476C6F7665722C204B6576696E3C2F617574686F723E3C617574686F723E476F626C652C204361726F6C653C2F617574686F723E3C617574686F723E476F64657269732C20416E746F6F6E3C2F617574686F723E3C617574686F723E48756C6C2C2044756E63616E3C2F617574686F723E3C617574686F723E4D617276696E2C2044617272656E3C2F617574686F723E3C617574686F723E4C692C2050657465723C2F617574686F723E3C617574686F723E4C6F72642C205068696C6C69703C2F617574686F723E3C617574686F723E506F636F636B2C204D61747468657720522E3C2F617574686F723E3C617574686F723E53656E6765722C204D617274696E3C2F617574686F723E3C617574686F723E53746576656E732C20526F626572743C2F617574686F723E3C617574686F723E57697061742C20416E696C3C2F617574686F723E3C617574686F723E57726F652C2043687269733C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E54617665726E613A206C6573736F6E7320696E206372656174696E67206120776F726B666C6F7720656E7669726F6E6D656E7420666F7220746865206C69666520736369656E6365733A2052657365617263682041727469636C65733C2F7469746C653E3C7365636F6E646172792D7469746C653E436F6E637572722E20436F6D7075742E203A2050726163742E2045787065722E3C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E313036372D313130303C2F70616765733E3C766F6C756D653E31383C2F766F6C756D653E3C6E756D6265723E31303C2F6E756D6265723E3C64617465733E3C796561723E323030363C2F796561723E3C2F64617465733E3C6C6162656C3E74617665726E613C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C2F456E644E6F74653E</w:data> </xml><![endif]--><!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->. Other systems monitor users&#8217; ad hoc executions <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Frew&lt;/Author&gt;&lt;Year&gt;2008&lt;/Year&gt;&lt;RecNum&gt;531&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;531&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;531&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Frew, James&lt;/author&gt;&lt;author&gt;Metzger, Dominic&lt;/author&gt;&lt;author&gt;Slaughter, Peter&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Automatic capture and reconstruction of computational provenance&lt;/title&gt;&lt;secondary-title&gt;Concurr. Comput. : Pract. Exper.&lt;/secondary-title&gt;&lt;/titles&gt;&lt;pages&gt;485-496&lt;/pages&gt;&lt;volume&gt;20&lt;/volume&gt;&lt;number&gt;5&lt;/number&gt;&lt;dates&gt;&lt;year&gt;2008&lt;/year&gt;&lt;/dates&gt;&lt;label&gt;frew08&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;Cite&gt;&lt;Author&gt;Muniswamy-Reddy&lt;/Author&gt;&lt;Year&gt;2006&lt;/Year&gt;&lt;RecNum&gt;552&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;552&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;552&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Muniswamy-Reddy, Kiran-Kumar&lt;/author&gt;&lt;author&gt;Holland, David A.&lt;/author&gt;&lt;author&gt;Braun, Uri&lt;/author&gt;&lt;author&gt;Seltzer, Margo I.&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Provenance-Aware Storage Systems&lt;/title&gt;&lt;secondary-title&gt;USENIX Annual Technical Conference&lt;/secondary-title&gt;&lt;/titles&gt;&lt;pages&gt;43-56&lt;/pages&gt;&lt;dates&gt;&lt;year&gt;2006&lt;/year&gt;&lt;/dates&gt;&lt;label&gt;muniswamy06&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[17, 24]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->. Lineage within databases <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Buneman&lt;/Author&gt;&lt;Year&gt;2007&lt;/Year&gt;&lt;RecNum&gt;618&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;618&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;618&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Buneman, Peter&lt;/author&gt;&lt;author&gt;Cheney, James&lt;/author&gt;&lt;author&gt;Vansummeren, Stijn&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;On the Expressiveness of Implicit Provenance in Query and Update Languages.&lt;/title&gt;&lt;secondary-title&gt;ICDT&lt;/secondary-title&gt;&lt;/titles&gt;&lt;pages&gt;209-223&lt;/pages&gt;&lt;dates&gt;&lt;year&gt;2007&lt;/year&gt;&lt;/dates&gt;&lt;label&gt;buneman07&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;Cite&gt;&lt;Author&gt;Benjelloun&lt;/Author&gt;&lt;Year&gt;2006&lt;/Year&gt;&lt;RecNum&gt;558&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;558&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;558&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Benjelloun, Omar&lt;/author&gt;&lt;author&gt;Sarma, Anish Das&lt;/author&gt;&lt;author&gt;Halevy, Alon&lt;/author&gt;&lt;author&gt;Widom, Jennifer&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;ULDBs: Databases with Uncertainty and Lineage&lt;/title&gt;&lt;secondary-title&gt;VLDB Seoul, Korea&lt;/secondary-title&gt;&lt;/titles&gt;&lt;pages&gt;953-964&lt;/pages&gt;&lt;dates&gt;&lt;year&gt;2006&lt;/year&gt;&lt;/dates&gt;&lt;label&gt;benjelloun06&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[4, 9]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->, mechanisms to help users query and navigate the lineage data <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Cohen-Boulakia&lt;/Author&gt;&lt;Year&gt;2008&lt;/Year&gt;&lt;RecNum&gt;664&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;664&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;664&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Cohen-Boulakia, Sarah&lt;/author&gt;&lt;author&gt;Biton, Olivier&lt;/author&gt;&lt;author&gt;Cohen, Shirley&lt;/author&gt;&lt;author&gt;Davidson, Susan&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Addressing the provenance challenge using ZOOM&lt;/title&gt;&lt;secondary-title&gt;Concurrency and Computation: Practice and Experience&lt;/secondary-title&gt;&lt;/titles&gt;&lt;pages&gt;497-506&lt;/pages&gt;&lt;volume&gt;20&lt;/volume&gt;&lt;dates&gt;&lt;year&gt;2008&lt;/year&gt;&lt;/dates&gt;&lt;label&gt;cohen08&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[14]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->, and topics such as lineage storage efficiency <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Chapman&lt;/Author&gt;&lt;Year&gt;2008&lt;/Year&gt;&lt;RecNum&gt;764&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;764&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;764&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Chapman, Adriane&lt;/author&gt;&lt;author&gt;Jagadish, H.V.&lt;/author&gt;&lt;author&gt;Ramanan, Prakash&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Efficient Provenance Storage&lt;/title&gt;&lt;secondary-title&gt;SIGMOD&lt;/secondary-title&gt;&lt;/titles&gt;&lt;pages&gt;993-1006&lt;/pages&gt;&lt;dates&gt;&lt;year&gt;2008&lt;/year&gt;&lt;/dates&gt;&lt;label&gt;chapman08&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[11]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]--> have also been explored. The Open Provenance Model (OPM) <!--[if supportFields]><span style='mso-element: field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Moreau&lt;/Author&gt;&lt;Year&gt;2007&lt;/Year&gt;&lt;RecNum&gt;573&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;573&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;573&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Report&quot;&gt;27&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Moreau, L.&lt;/author&gt;&lt;author&gt;Freire, J.&lt;/author&gt;&lt;author&gt;Futrelle, J.&lt;/author&gt;&lt;author&gt;McGrath, R.&lt;/author&gt;&lt;author&gt;Myers, J.&lt;/author&gt;&lt;author&gt;Paulson, P.&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;The Open Provenance Model&lt;/title&gt;&lt;/titles&gt;&lt;dates&gt;&lt;year&gt;2007&lt;/year&gt;&lt;/dates&gt;&lt;publisher&gt;University of Southampton&lt;/publisher&gt;&lt;label&gt;provmodelreport&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[22]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]--> is a high level attempt to model generic lineage graphs and their component artifacts, processes and edges.</p> <p class=MsoNormal>As lineage systems gain traction, they will be used with sensitive data and processes, e.g. medical data <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Stef-Praun&lt;/Author&gt;&lt;Year&gt;2007&lt;/Year&gt;&lt;RecNum&gt;638&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;638&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;638&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Stef-Praun, T.&lt;/author&gt;&lt;author&gt;Clifford, B.&lt;/author&gt;&lt;author&gt;Foster, Ian&lt;/author&gt;&lt;author&gt;Hasson, U.&lt;/author&gt;&lt;author&gt;Hategan, M.&lt;/author&gt;&lt;author&gt;Small, S.&lt;/author&gt;&lt;author&gt;Wilde, Micheal&lt;/author&gt;&lt;author&gt;Zhao, Y.&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Accelerating Medical Research using the Swift Workflow System&lt;/title&gt;&lt;secondary-title&gt;Health Grid&lt;/secondary-title&gt;&lt;/titles&gt;&lt;dates&gt;&lt;year&gt;2007&lt;/year&gt;&lt;/dates&gt;&lt;label&gt;stefpraun07&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;Cite&gt;&lt;Author&gt;Anderson&lt;/Author&gt;&lt;Year&gt;2006&lt;/Year&gt;&lt;RecNum&gt;591&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;591&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;591&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Report&quot;&gt;27&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Anderson, Erik W.&lt;/author&gt;&lt;author&gt;Callahan, Steven P.&lt;/author&gt;&lt;author&gt;Chen, George T. Y.&lt;/author&gt;&lt;author&gt;Freire, Juliana&lt;/author&gt;&lt;author&gt;Santos, Emanuele&lt;/author&gt;&lt;author&gt;Scheidegger, Carlos E.&lt;/author&gt;&lt;author&gt;Silva, Claudio T.&lt;/author&gt;&lt;author&gt;Vo, Huy T.&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Visualization in Radiation Oncology: Towards Replacing the Laboratory Notebook&lt;/title&gt;&lt;/titles&gt;&lt;dates&gt;&lt;year&gt;2006&lt;/year&gt;&lt;/dates&gt;&lt;publisher&gt;SCI Institute Technical Report, No. UUSCI-2006-17, University of Utah&lt;/publisher&gt;&lt;label&gt;anderson06&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[3, 28]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->. The need for secure lineage is outlined in <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE <span style='mso-element: field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE.DATA <![if gte mso 9]><xml> <w:data>3C456E644E6F74653E3C436974653E3C417574686F723E486173616E3C2F417574686F723E3C596561723E323030373C2F596561723E3C5265634E756D3E3735323C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3735323C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3735323C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E486173616E2C20522E3C2F617574686F723E3C617574686F723E53696F6E2C20522E3C2F617574686F723E3C617574686F723E57696E736C6574742C204D2E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E496E74726F647563696E67205365637572652050726F76656E616E63653A2050726F626C656D7320616E64204368616C6C656E6765733C2F7469746C653E3C7365636F6E646172792D7469746C653E50726F63656564696E6773206F662074686520546869726420496E7465726E6174696F6E616C20576F726B73686F70206F6E2053746F7261676520536563757269747920616E64205375727669766162696C6974793C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C64617465733E3C796561723E323030373C2F796561723E3C2F64617465733E3C6C6162656C3E686173616E30373C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E486173616E3C2F417574686F723E3C596561723E323030373C2F596561723E3C5265634E756D3E3735323C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3735323C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3735323C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E486173616E2C20522E3C2F617574686F723E3C617574686F723E53696F6E2C20522E3C2F617574686F723E3C617574686F723E57696E736C6574742C204D2E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E496E74726F647563696E67205365637572652050726F76656E616E63653A2050726F626C656D7320616E64204368616C6C656E6765733C2F7469746C653E3C7365636F6E646172792D7469746C653E50726F63656564696E6773206F662074686520546869726420496E7465726E6174696F6E616C20576F726B73686F70206F6E2053746F7261676520536563757269747920616E64205375727669766162696C6974793C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C64617465733E3C796561723E323030373C2F796561723E3C2F64617465733E3C6C6162656C3E686173616E30373C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E427261756E3C2F417574686F723E3C596561723E323030383C2F596561723E3C5265634E756D3E3737393C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3737393C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3737393C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D22436F6E666572656E63652050726F63656564696E6773223E31303C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E55726920427261756E3C2F617574686F723E3C617574686F723E417661726168616D205368696E6E61723C2F617574686F723E3C617574686F723E4D6172676F2053656C747A65723C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E5365637572696E672050726F76656E616E63653C2F7469746C653E3C7365636F6E646172792D7469746C653E5553454E495820486F745365633C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C64617465733E3C796561723E323030383C2F796561723E3C2F64617465733E3C75726C733E3C2F75726C733E3C637573746F6D323E323030383C2F637573746F6D323E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E54616E3C2F417574686F723E3C596561723E323030363C2F596561723E3C5265634E756D3E3732343C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3732343C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3732343C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D22436F6E666572656E63652050726F63656564696E6773223E31303C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E54616E2C20562E3C2F617574686F723E3C617574686F723E47726F74682C20502E3C2F617574686F723E3C617574686F723E4D696C65732C20532E3C2F617574686F723E3C617574686F723E4A69616E672C20532E3C2F617574686F723E3C617574686F723E4D756E726F652C20532E3C2F617574686F723E3C617574686F723E54736173616B6F752C20532E3C2F617574686F723E3C617574686F723E4D6F726561752C204C2E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E53656375726974792049737375657320696E206120534F412D42617365642050726F76656E616E63652053797374656D3C2F7469746C653E3C616C742D7469746C653E4C656374757265204E6F74657320696E20436F6D707574657220536369656E63653C2F616C742D7469746C653E3C2F7469746C65733E3C616C742D706572696F646963616C3E3C66756C6C2D7469746C653E4C656374757265204E6F74657320696E20436F6D707574657220536369656E63653C2F66756C6C2D7469746C653E3C2F616C742D706572696F646963616C3E3C64617465733E3C796561723E323030363C2F796561723E3C2F64617465733E3C7075626C69736865723E537072696E676572204265726C696E202F2048656964656C626572673C2F7075626C69736865723E3C6C6162656C3E74616E30363C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E426C6175737465696E3C2F417574686F723E3C596561723E323030383C2F596561723E3C5265634E756D3E3432313C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3432313C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3432313C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E426C6175737465696E2C204261726261726120542E3C2F617574686F723E3C617574686F723E53656C69676D616E2C204C656E3C2F617574686F723E3C617574686F723E4D6F7273652C204D69636861656C3C2F617574686F723E3C617574686F723E416C6C656E2C204D2E2044617669643C2F617574686F723E3C617574686F723E526F73656E7468616C2C2041726E6F6E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C617574682D616464726573733E44424C502C20687474703A2F2F64626C702E756E692D74726965722E64653C2F617574682D616464726573733E3C7469746C65733E3C7469746C653E504C55533A2053796E74686573697A696E6720707269766163792C206C696E656167652C20756E6365727461696E747920616E642073656375726974793C2F7469746C653E3C7365636F6E646172792D7469746C653E4943444520576F726B73686F70733C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E3234322D3234353C2F70616765733E3C64617465733E3C796561723E323030383C2F796561723E3C2F64617465733E3C7075626C69736865723E4945454520436F6D707574657220536F63696574793C2F7075626C69736865723E3C6C6162656C3E44424C503A636F6E662F696364652F426C6175737465696E534D415230383C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C2F456E644E6F74653E</w:data> </xml><![endif]><span style='mso-element:field-end'></span><span style='mso-element:field-separator'></span><![endif]-->[6, 8, 18, 29]<!--[if gte mso 9]><xml> <w:data>3C456E644E6F74653E3C436974653E3C417574686F723E486173616E3C2F417574686F723E3C596561723E323030373C2F596561723E3C5265634E756D3E3735323C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3735323C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3735323C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E486173616E2C20522E3C2F617574686F723E3C617574686F723E53696F6E2C20522E3C2F617574686F723E3C617574686F723E57696E736C6574742C204D2E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E496E74726F647563696E67205365637572652050726F76656E616E63653A2050726F626C656D7320616E64204368616C6C656E6765733C2F7469746C653E3C7365636F6E646172792D7469746C653E50726F63656564696E6773206F662074686520546869726420496E7465726E6174696F6E616C20576F726B73686F70206F6E2053746F7261676520536563757269747920616E64205375727669766162696C6974793C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C64617465733E3C796561723E323030373C2F796561723E3C2F64617465733E3C6C6162656C3E686173616E30373C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E486173616E3C2F417574686F723E3C596561723E323030373C2F596561723E3C5265634E756D3E3735323C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3735323C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3735323C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E486173616E2C20522E3C2F617574686F723E3C617574686F723E53696F6E2C20522E3C2F617574686F723E3C617574686F723E57696E736C6574742C204D2E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E496E74726F647563696E67205365637572652050726F76656E616E63653A2050726F626C656D7320616E64204368616C6C656E6765733C2F7469746C653E3C7365636F6E646172792D7469746C653E50726F63656564696E6773206F662074686520546869726420496E7465726E6174696F6E616C20576F726B73686F70206F6E2053746F7261676520536563757269747920616E64205375727669766162696C6974793C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C64617465733E3C796561723E323030373C2F796561723E3C2F64617465733E3C6C6162656C3E686173616E30373C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E427261756E3C2F417574686F723E3C596561723E323030383C2F596561723E3C5265634E756D3E3737393C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3737393C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3737393C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D22436F6E666572656E63652050726F63656564696E6773223E31303C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E55726920427261756E3C2F617574686F723E3C617574686F723E417661726168616D205368696E6E61723C2F617574686F723E3C617574686F723E4D6172676F2053656C747A65723C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E5365637572696E672050726F76656E616E63653C2F7469746C653E3C7365636F6E646172792D7469746C653E5553454E495820486F745365633C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C64617465733E3C796561723E323030383C2F796561723E3C2F64617465733E3C75726C733E3C2F75726C733E3C637573746F6D323E323030383C2F637573746F6D323E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E54616E3C2F417574686F723E3C596561723E323030363C2F596561723E3C5265634E756D3E3732343C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3732343C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3732343C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D22436F6E666572656E63652050726F63656564696E6773223E31303C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E54616E2C20562E3C2F617574686F723E3C617574686F723E47726F74682C20502E3C2F617574686F723E3C617574686F723E4D696C65732C20532E3C2F617574686F723E3C617574686F723E4A69616E672C20532E3C2F617574686F723E3C617574686F723E4D756E726F652C20532E3C2F617574686F723E3C617574686F723E54736173616B6F752C20532E3C2F617574686F723E3C617574686F723E4D6F726561752C204C2E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C7469746C65733E3C7469746C653E53656375726974792049737375657320696E206120534F412D42617365642050726F76656E616E63652053797374656D3C2F7469746C653E3C616C742D7469746C653E4C656374757265204E6F74657320696E20436F6D707574657220536369656E63653C2F616C742D7469746C653E3C2F7469746C65733E3C616C742D706572696F646963616C3E3C66756C6C2D7469746C653E4C656374757265204E6F74657320696E20436F6D707574657220536369656E63653C2F66756C6C2D7469746C653E3C2F616C742D706572696F646963616C3E3C64617465733E3C796561723E323030363C2F796561723E3C2F64617465733E3C7075626C69736865723E537072696E676572204265726C696E202F2048656964656C626572673C2F7075626C69736865723E3C6C6162656C3E74616E30363C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C436974653E3C417574686F723E426C6175737465696E3C2F417574686F723E3C596561723E323030383C2F596561723E3C5265634E756D3E3432313C2F5265634E756D3E3C7265636F72643E3C7265632D6E756D6265723E3432313C2F7265632D6E756D6265723E3C666F726569676E2D6B6579733E3C6B6579206170703D22454E222064622D69643D2274786530786430746978746535376565617472357A6664383264393030667A7235667676223E3432313C2F6B65793E3C2F666F726569676E2D6B6579733E3C7265662D74797065206E616D653D224A6F75726E616C2041727469636C65223E31373C2F7265662D747970653E3C636F6E7472696275746F72733E3C617574686F72733E3C617574686F723E426C6175737465696E2C204261726261726120542E3C2F617574686F723E3C617574686F723E53656C69676D616E2C204C656E3C2F617574686F723E3C617574686F723E4D6F7273652C204D69636861656C3C2F617574686F723E3C617574686F723E416C6C656E2C204D2E2044617669643C2F617574686F723E3C617574686F723E526F73656E7468616C2C2041726E6F6E3C2F617574686F723E3C2F617574686F72733E3C2F636F6E7472696275746F72733E3C617574682D616464726573733E44424C502C20687474703A2F2F64626C702E756E692D74726965722E64653C2F617574682D616464726573733E3C7469746C65733E3C7469746C653E504C55533A2053796E74686573697A696E6720707269766163792C206C696E656167652C20756E6365727461696E747920616E642073656375726974793C2F7469746C653E3C7365636F6E646172792D7469746C653E4943444520576F726B73686F70733C2F7365636F6E646172792D7469746C653E3C2F7469746C65733E3C70616765733E3234322D3234353C2F70616765733E3C64617465733E3C796561723E323030383C2F796561723E3C2F64617465733E3C7075626C69736865723E4945454520436F6D707574657220536F63696574793C2F7075626C69736865723E3C6C6162656C3E44424C503A636F6E662F696364652F426C6175737465696E534D415230383C2F6C6162656C3E3C75726C733E3C2F75726C733E3C2F7265636F72643E3C2F436974653E3C2F456E644E6F74653E</w:data> </xml><![endif]--><!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->. The current body of research can be broken out into three general categories: securing the underlying lineage information from tamper <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Zhang&lt;/Author&gt;&lt;Year&gt;2009&lt;/Year&gt;&lt;RecNum&gt;768&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;768&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;768&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Zhang, Jing&lt;/author&gt;&lt;author&gt;Chapman, Adriane&lt;/author&gt;&lt;author&gt;LeFevre, Kristen&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Fine-Grained Tamper-Evident Data Pedigree&lt;/title&gt;&lt;secondary-title&gt;University of Michigan Technical Report&lt;/secondary-title&gt;&lt;/titles&gt;&lt;periodical&gt;&lt;full-title&gt;University of Michigan Technical Report&lt;/full-title&gt;&lt;/periodical&gt;&lt;dates&gt;&lt;year&gt;2009&lt;/year&gt;&lt;/dates&gt;&lt;label&gt;zhang08&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[32]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->; enforcing expected behavior <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Khan&lt;/Author&gt;&lt;Year&gt;2006&lt;/Year&gt;&lt;RecNum&gt;727&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;727&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;727&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Conference Proceedings&quot;&gt;10&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Khan, I.&lt;/author&gt;&lt;author&gt;Schroeter, R.&lt;/author&gt;&lt;author&gt;Hunter, J.&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Implementing a Secure Annotation Service&lt;/title&gt;&lt;alt-title&gt;Lecture Notes in Computer Science&lt;/alt-title&gt;&lt;/titles&gt;&lt;alt-periodical&gt;&lt;full-title&gt;Lecture Notes in Computer Science&lt;/full-title&gt;&lt;/alt-periodical&gt;&lt;dates&gt;&lt;year&gt;2006&lt;/year&gt;&lt;/dates&gt;&lt;publisher&gt;Springer Berlin / Heidelberg&lt;/publisher&gt;&lt;label&gt;khan06&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[19]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->, and specifying access controls. Several groups have proposed access control models for lineage. In <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Tsai&lt;/Author&gt;&lt;Year&gt;2007&lt;/Year&gt;&lt;RecNum&gt;726&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;726&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;726&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Tsai, W. T.&lt;/author&gt;&lt;author&gt;Wei, X.&lt;/author&gt;&lt;author&gt;Chen, Y.&lt;/author&gt;&lt;author&gt;Paul, R.&lt;/author&gt;&lt;author&gt;Chung, J.-Y.&lt;/author&gt;&lt;author&gt;Zhang, D.&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Data provenance in SOA: security, reliability, and integrity&lt;/title&gt;&lt;secondary-title&gt;Journal Service Oriented Computing and Applications&lt;/secondary-title&gt;&lt;/titles&gt;&lt;dates&gt;&lt;year&gt;2007&lt;/year&gt;&lt;/dates&gt;&lt;label&gt;tsai07&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[30]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->, a high level overview of security concerns in a SOA environment are presented. In particular, a basic access control policy that allows users to access lineage nodes if the level(user) &#8805; level(node). <!--[if supportFields]><span style='mso-element: field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Braun&lt;/Author&gt;&lt;Year&gt;2006&lt;/Year&gt;&lt;RecNum&gt;778&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;778&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;778&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Unpublished Work&quot;&gt;34&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Uri Braun&lt;/author&gt;&lt;author&gt;Avi Shinnar&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;A Security Model for Provenance&lt;/title&gt;&lt;secondary-title&gt;Technical Report&lt;/secondary-title&gt;&lt;/titles&gt;&lt;volume&gt;TR-04-06&lt;/volume&gt;&lt;dates&gt;&lt;year&gt;2006&lt;/year&gt;&lt;/dates&gt;&lt;publisher&gt;Harvard University Computer Science&lt;/publisher&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[7]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]--> breaks lineage information into nodes and edges, specifying a RBAC policy for distinct lineage information. In a different take, <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Cirillo&lt;/Author&gt;&lt;Year&gt;2008&lt;/Year&gt;&lt;RecNum&gt;725&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;725&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;725&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Conference Proceedings&quot;&gt;10&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Cirillo, A.&lt;/author&gt;&lt;author&gt;Jagadeesan, R.&lt;/author&gt;&lt;author&gt;Pitcher, C.&lt;/author&gt;&lt;author&gt;Riely, J.&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Tapido: Trust and Authorization Via Provenance and Integrity in Distributed Objects&lt;/title&gt;&lt;alt-title&gt;Lecture Notes in Computer Science&lt;/alt-title&gt;&lt;/titles&gt;&lt;alt-periodical&gt;&lt;full-title&gt;Lecture Notes in Computer Science&lt;/full-title&gt;&lt;/alt-periodical&gt;&lt;dates&gt;&lt;year&gt;2008&lt;/year&gt;&lt;/dates&gt;&lt;label&gt;cirillo08&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[13]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]--> utilizes information about the past ownership of an object (or lineage) to determine whether or not a data object should be released. Finally, <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Chebotko&lt;/Author&gt;&lt;Year&gt;2008&lt;/Year&gt;&lt;RecNum&gt;723&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;723&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;723&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Chebotko, Artem&lt;/author&gt;&lt;author&gt;Chang, Seunghan&lt;/author&gt;&lt;author&gt;Lu, Shiyong&lt;/author&gt;&lt;author&gt;Fotouhi, Farshad&lt;/author&gt;&lt;author&gt;Yang, Ping&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Scientific Workflow Provenance Querying with Security Views&lt;/title&gt;&lt;secondary-title&gt;WAIM&lt;/secondary-title&gt;&lt;/titles&gt;&lt;dates&gt;&lt;year&gt;2008&lt;/year&gt;&lt;/dates&gt;&lt;label&gt;chebotko08&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[12]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]--> uses role-based access control, and explores how to release lineage views based on this model. Our work is the first to explore application of fine-grained ABAC to lineage information. </p> <h2><![if !supportLists]>4.2. <![endif]>Security models </h2> <p class=MsoNormal style='margin-bottom:6.0pt;text-indent:0pt'>Access control lists simply designate which users may access each object. Role-based access control (RBAC) offers a major improvement over access control lists and is used in many systems. Two simple forms are specified by the NIST <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Ferraiolo&lt;/Author&gt;&lt;Year&gt;2004&lt;/Year&gt;&lt;RecNum&gt;785&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;785&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;785&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Book&quot;&gt;6&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;D. Ferraiolo&lt;/author&gt;&lt;author&gt;R. Kuhn&lt;/author&gt;&lt;author&gt;R. Chandramouli&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Role Based Access Control&lt;/title&gt;&lt;/titles&gt;&lt;dates&gt;&lt;year&gt;2004&lt;/year&gt;&lt;/dates&gt;&lt;publisher&gt;Artech House&lt;/publisher&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[16]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]--> and SQL standards, and in many application server and DBMS products. Dozens of extensions have been proposed, e.g. GTRBAC <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Bhatti&lt;/Author&gt;&lt;Year&gt;2004&lt;/Year&gt;&lt;RecNum&gt;786&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;786&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;786&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Conference Proceedings&quot;&gt;10&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Rafae Bhatti&lt;/author&gt;&lt;author&gt;James Joshi&lt;/author&gt;&lt;author&gt;Elisa Bertino&lt;/author&gt;&lt;author&gt;Arif Ghafoor&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;X-GTRBAC Admin: A Decentralized Administration Model for Enterprise Wide Access Control&lt;/title&gt;&lt;secondary-title&gt;ACM SACMAT&lt;/secondary-title&gt;&lt;/titles&gt;&lt;pages&gt;78-86&lt;/pages&gt;&lt;dates&gt;&lt;year&gt;2004&lt;/year&gt;&lt;/dates&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[5]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->, but they have gained little industrial traction. In general, RBAC suffers from scalability problems since security administrators must maintain their own up-to-date model of resources and users <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Rosenthal&lt;/Author&gt;&lt;Year&gt;2006&lt;/Year&gt;&lt;RecNum&gt;787&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;787&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;787&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Book Section&quot;&gt;5&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Arnon Rosenthal&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Scalable Access Policy Administration: Opinions and a Research Agenda &lt;/title&gt;&lt;secondary-title&gt;Security Management, Integrity, and Internal Control in Information Systems&lt;/secondary-title&gt;&lt;tertiary-title&gt;IFIP International Federation for Information Processing&lt;/tertiary-title&gt;&lt;/titles&gt;&lt;pages&gt;355-370&lt;/pages&gt;&lt;dates&gt;&lt;year&gt;2006&lt;/year&gt;&lt;/dates&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[26]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->. SQL and XML security models both handle structured data. SQL protections (role based controls to table, column, or row) are insufficient to provide a convenient basis for securing lineage information; cell-granularity extensions are immature <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;LeFevre&lt;/Author&gt;&lt;Year&gt;2004&lt;/Year&gt;&lt;RecNum&gt;790&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;790&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;790&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Conference Proceedings&quot;&gt;10&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Kristen LeFevre&lt;/author&gt;&lt;author&gt;Rakesh Agarwal&lt;/author&gt;&lt;author&gt;Vuk Ercegovac&lt;/author&gt;&lt;author&gt;Raghu Ramakrishnan&lt;/author&gt;&lt;author&gt;Yirong Xu&lt;/author&gt;&lt;author&gt;David J. DeWitt&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;Limiting Disclosure in Hippocratic Databases&lt;/title&gt;&lt;secondary-title&gt;VLDB&lt;/secondary-title&gt;&lt;/titles&gt;&lt;pages&gt;108-119&lt;/pages&gt;&lt;dates&gt;&lt;year&gt;2004&lt;/year&gt;&lt;/dates&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[20]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->. Furthermore, one cannot easily express general predicates directly (and use of a separate view for each user profile is too awkward). Also, there is no construct for two administrators to share control over a policy. XML security is less mature and less standardized than SQL security. It is also more complex, since it addresses nesting and paths in trees, e.g. to authorize a node to be bypassed so its children remain visible <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Makoto&lt;/Author&gt;&lt;Year&gt;2006&lt;/Year&gt;&lt;RecNum&gt;793&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;793&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;793&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Makoto, Murata&lt;/author&gt;&lt;author&gt;Akihiko, Tozawa&lt;/author&gt;&lt;author&gt;Michiharu, Kudo&lt;/author&gt;&lt;author&gt;Satoshi, Hada&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;titles&gt;&lt;title&gt;XML access control using static analysis&lt;/title&gt;&lt;secondary-title&gt;ACM Trans. Inf. Syst. Secur.&lt;/secondary-title&gt;&lt;/titles&gt;&lt;periodical&gt;&lt;full-title&gt;ACM Trans. Inf. Syst. Secur.&lt;/full-title&gt;&lt;/periodical&gt;&lt;pages&gt;292-324&lt;/pages&gt;&lt;volume&gt;9&lt;/volume&gt;&lt;number&gt;3&lt;/number&gt;&lt;dates&gt;&lt;year&gt;2006&lt;/year&gt;&lt;/dates&gt;&lt;isbn&gt;1094-9224&lt;/isbn&gt;&lt;urls&gt;&lt;/urls&gt;&lt;electronic-resource-num&gt;http://doi.acm.org/10.1145/1178618.1178621&lt;/electronic-resource-num&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[21]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->.</p> <h1><a name="_Ref216498641"><![if !supportLists]>5. <![endif]>Conclusions</a></h1> <p class=NormalPost-Header style='margin-bottom:0pt;margin-bottom:.0001pt'>Among our users, we have encountered diverse needs for securing lineage information. Our approach emphasizes general purpose constructs for both lineage and security models, thereby giving vendors more incentive to build, and users more incentive to learn. At the same time, the general constructs are well suited to extension, customization, and traceability. </p> <p class=MsoNormal>We have suggested that the lineage community move to attribute-based access controls, which are more flexible than roles in situations where an access predicate tests multiple kinds of information. We also saw that predicate expressions were a convenient way to combine multiple concerns into a decision rule. </p> <p class=MsoNormal>We believe that concerns need to be managed explicitly, so their associated predicates can be separately explained, updated, validated, and audited. From here, it is a small step to managing the split of concerns and delegation of parts of it. We propose defaults that are suited to lineage systems.</p> <p class=MsoNormal>We are implementing these access control techniques within the PLUS system <!--[if supportFields]><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.CITE &lt;EndNote&gt;&lt;Cite&gt;&lt;Author&gt;Blaustein&lt;/Author&gt;&lt;Year&gt;2008&lt;/Year&gt;&lt;RecNum&gt;421&lt;/RecNum&gt;&lt;record&gt;&lt;rec-number&gt;421&lt;/rec-number&gt;&lt;foreign-keys&gt;&lt;key app=&quot;EN&quot; db-id=&quot;txe0xd0tixte57eeatr5zfd82d900fzr5fvv&quot;&gt;421&lt;/key&gt;&lt;/foreign-keys&gt;&lt;ref-type name=&quot;Journal Article&quot;&gt;17&lt;/ref-type&gt;&lt;contributors&gt;&lt;authors&gt;&lt;author&gt;Blaustein, Barbara T.&lt;/author&gt;&lt;author&gt;Seligman, Len&lt;/author&gt;&lt;author&gt;Morse, Michael&lt;/author&gt;&lt;author&gt;Allen, M. David&lt;/author&gt;&lt;author&gt;Rosenthal, Arnon&lt;/author&gt;&lt;/authors&gt;&lt;/contributors&gt;&lt;auth-address&gt;DBLP, http://dblp.uni-trier.de&lt;/auth-address&gt;&lt;titles&gt;&lt;title&gt;PLUS: Synthesizing privacy, lineage, uncertainty and security&lt;/title&gt;&lt;secondary-title&gt;ICDE Workshops&lt;/secondary-title&gt;&lt;/titles&gt;&lt;pages&gt;242-245&lt;/pages&gt;&lt;dates&gt;&lt;year&gt;2008&lt;/year&gt;&lt;/dates&gt;&lt;publisher&gt;IEEE Computer Society&lt;/publisher&gt;&lt;label&gt;DBLP:conf/icde/BlausteinSMAR08&lt;/label&gt;&lt;urls&gt;&lt;/urls&gt;&lt;/record&gt;&lt;/Cite&gt;&lt;/EndNote&gt;<span style='mso-element:field-separator'></span><![endif]-->[6]<!--[if supportFields]><span style='mso-element:field-end'></span><![endif]-->. For administration and also run-time efficiency, our prototype lets an administrator or stakeholder choose a set of items and attach the same predicate to all of them. We have identified a set of default concerns and their stakeholders; administrators may add additional ones. At the time of this writing, we use simple conjunctions &#8211; vetoes &#8211; for all combinations of concerns. Meanwhile, we demonstrate our prototype frequently to potential users of lineage information, and are gathering requirements and reactions. </p> <p class=MsoNormal>Based on this information, we are investigating &#8220;surrogate&#8221; answers &#8211; a general facility that, when a user is unable to access some of the desired information, gives approximate or other answers that can help. Additionally, we plan to exploit the modular specification of access control predicates to explain authorization failures&#8212;e.g. the concerns about privacy of patient medical information were satisfied, but not those pertaining to financial information.</p> <p class=AbstractHeading>References</p> <p class=MsoNormal style='margin-left:36.0pt;text-indent:-36.0pt'><!--[if supportFields]><span style='font-size:9.0pt'><span style='mso-element:field-begin'></span><span style="mso-spacerun: yes">&nbsp;</span>ADDIN EN.REFLIST <span style='mso-element: field-separator'></span></span><![endif]--><span style='font-size:9.0pt'>[1]<span style='mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>&quot;SAML,&quot; </span><a href="http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=security"><span style='font-size:9.0pt;color:windowtext;text-decoration:none;text-underline: none'>http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=security</span></a><span style='font-size:9.0pt'>.<o:p></o:p></span></p> <p class=MsoNormal style='margin-left:36.0pt;text-indent:-36.0pt'><span style='font-size:9.0pt'>[2]<span style='mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>&quot;XACML,&quot; </span><a href="http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=xacml"><span style='font-size:9.0pt;color:windowtext;text-decoration:none;text-underline: none'>http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=xacml</span></a><span style='font-size:9.0pt'>.<o:p></o:p></span></p> <p class=MsoNormal style='margin-left:36.0pt;text-indent:-36.0pt'><span style='font-size:9.0pt'>[3]<span style='mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>E. W. Anderson, S. P. Callahan, G. T. Y. Chen, J. Freire, E. Santos, C. E. Scheidegger, C. T. Silva, and H. T. Vo, &quot;Visualization in Radiation Oncology: Towards Replacing the Laboratory Notebook,&quot; SCI Institute Technical Report, No. UUSCI-2006-17, University of Utah 2006.<o:p></o:p></span></p> <p class=MsoNormal style='margin-left:36.0pt;text-indent:-36.0pt'><span style='font-size:9.0pt'>[4]<span style='mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>O. Benjelloun, A. D. Sarma, A. Halevy, and J. Widom, &quot;ULDBs: Databases with Uncertainty and Lineage,&quot; <i>VLDB Seoul, Korea</i></span><span style='font-size:9.0pt'>, pp. 953-964, 2006.<o:p></o:p></span></p> <p class=MsoNormal style='margin-left:36.0pt;text-indent:-36.0pt'><span style='font-size:9.0pt'>[5]<span style='mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>R. Bhatti, J. Joshi, E. Bertino, and A. Ghafoor, &quot;X-GTRBAC Admin: A Decentralized Administration Model for Enterprise Wide Access Control,&quot; X-GTRBAC Admin: A Decentralized Administration Model for Enterprise Wide Access Control, 2004.<o:p></o:p></span></p> <p class=MsoNormal style='margin-left:36.0pt;text-indent:-36.0pt'><span style='font-size:9.0pt'>[6]<span style='mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>B. T. Blaustein, L. Seligman, M. Morse, M. D. Allen, and A. Rosenthal, &quot;PLUS: Synthesizing privacy, lineage, uncertainty and security,&quot; <i>ICDE Workshops</i></span><span style='font-size:9.0pt'>, pp. 242-245, 2008.<o:p></o:p></span></p> <p class=MsoNormal style='margin-left:36.0pt;text-indent:-36.0pt'><span style='font-size:9.0pt'>[7]<span style='mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>U. Braun and A. Shinnar, &quot;A Security Model for Provenance,&quot; in <i>Technical Report</i></span><span style='font-size:9.0pt'>, vol. TR-04-06: Harvard University Computer Science, 2006.<o:p></o:p></span></p> <p class=MsoNormal style='margin-left:36.0pt;text-indent:-36.0pt'><span style='font-size:9.0pt'>[8]<span style='mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>U. Braun, A. Shinnar, and M. Seltzer, &quot;Securing Provenance,&quot; Securing Provenance, 2008.<o:p></o:p></span></p> <p class=MsoNormal style='margin-left:36.0pt;text-indent:-36.0pt'><span style='font-size:9.0pt'>[9]<span style='mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>P. Buneman, J. Cheney, and S. Vansummeren, &quot;On the Expressiveness of Implicit Provenance in Query and Update Languages.,&quot; <i>ICDT</i></span><span style='font-size:9.0pt'>, pp. 209-223, 2007.<o:p></o:p></span></p> <p class=MsoNormal style='margin-left:36.0pt;text-indent:-36.0pt'><span style='font-size:9.0pt'>[10]<span style='mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>S. P. Callahan, J. Freire, E. Santos, C. E. Scheidegger, and C. T. S. H. T. Vo, &quot;VisTrails: Visualization meets Data Management,&quot; <i>SIGMOD</i></span><span style='font-size:9.0pt'>, pp. 745-747, 2006.<o:p></o:p></span></p> <p class=MsoNormal style='margin-left:36.0pt;text-indent:-36.0pt'><span style='font-size:9.0pt'>[11]<span style='mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>A. Chapman, H. V. Jagadish, and P. Ramanan, &quot;Efficient Provenance Storage,&quot; <i>SIGMOD</i></span><span style='font-size:9.0pt'>, pp. 993-1006, 2008.<o:p></o:p></span></p> <p class=MsoNormal style='margin-left:36.0pt;text-indent:-36.0pt'><span style='font-size:9.0pt'>[12]<span style='mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>A. Chebotko, S. Chang, S. Lu, F. Fotouhi, and P. Yang, &quot;Scientific Workflow Provenance Querying with Security Views,&quot; <i>WAIM</i></span><span style='font-size:9.0pt'>, 2008.<o:p></o:p></span></p> <p class=MsoNormal style='margin-left:36.0pt;text-indent:-36.0pt'><span style='font-size:9.0pt'>[13]<span style='mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>A. Cirillo, R. Jagadeesan, C. Pitcher, and J. Riely, &quot;Tapido: Trust and Authorization Via Provenance and Integrity in Distributed Objects,&quot; Tapido: Trust and Authorization Via Provenance and Integrity in Distributed Objects, 2008.<o:p></o:p></span></p> <p class=MsoNormal style='margin-left:36.0pt;text-indent:-36.0pt'><span style='font-size:9.0pt'>[14]<span style='mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>S. Cohen-Boulakia, O. Biton, S. Cohen, and S. Davidson, &quot;Addressing the provenance challenge using ZOOM,&quot; <i>Concurrency and Computation: Practice and Experience</i></span><span style='font-size:9.0pt'>, vol. 20, pp. 497-506, 2008.<o:p></o:p></span></p> <p class=MsoNormal style='margin-left:36.0pt;text-indent:-36.0pt'><span style='font-size:9.0pt'>[15]<span style='mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>S. Davidson, S. Cohen-Boulakia, A. Eyal, B. Ludascher, T. McPhillips, S. Bowers, and J. Freire, &quot;Provenance in Scientific Workflow Systems,&quot; <i>IEEE Data Engineering Bulletin</i></span><span style='font-size:9.0pt'>, vol. 32, pp. 44-50, 2007.<o:p></o:p></span></p> <p class=MsoNormal style='margin-left:36.0pt;text-indent:-36.0pt'><span style='font-size:9.0pt'>[16]<span style='mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>D. Ferraiolo, R. Kuhn, and R. Chandramouli, <i>Role Based Ac