Ensuring privacy in virtual knowledge graphs
2026 (English)Doctoral thesis, comprehensive summary (Other academic)Alternative title
Säkerställande av integritet i virtuella kunskapsgrafer (Swedish)
Abstract [en]
Virtual Knowledge Graphs (VKGs), also known as Ontology-Based Data Access (OBDA), provide a paradigm for querying data sources, typically relational databases, through a conceptual layer defined by an ontology. Classes and properties in the ontology are connected to the underlying data sources through declarative mappings. VKGs are increasingly used for data management in domains such as healthcare, where the abundance and sensitivity of data raise important concerns about the confidentiality of stored information. Controlled Query Evaluation (CQE) addresses confidentiality through a confidentiality policy, which represents the information that must be protected, and a censor, which modifies query answers so that a user cannot infer information whose disclosure would violate the policy. Policy-Protected VKGs (PPVKGs) integrate CQE into the VKG paradigm by embedding the confidentiality policy directly into the mappings. Although the theoretical foundations of this approach are well established, it had not been realized on an open-source VKG system, and it was not known whether the framework could support the broader privacy requirements of a real, regulated organization. This thesis investigates these limitations from implementation, regulatory, and access-control perspectives through four contributions: an open-source realization of PPVKGs, an assessment of their adequacy against health care privacy requirements, role-based access control for differentiated access, and Break-the-Glass mechanisms for controlled emergency access. Health care isused as the setting throughout the thesis because hospitals already use ontologies as a data access layer and operate under detailed legal and organizational requirements. The results show that PPVKGs can provide strong protection against inference over sensitive combinations of facts and can do so while retaining the existing VKG query engine and practical query performance. At the same time, the assessment identifies structural limitations: the framework cannot transform values, modify the underlying source, or make disclosure depend on the identity of the requester or exceptional circumstances. The thesis addresses the latter limitations through role-based and emergency access mechanisms implemented at the mapping level, preserving the confidentiality of the underlying PPVKG framework. Together, these results establish an open source and extensible foundation for privacy-aware VKGs while also clarifying the limits of what can be achieved through mapping-level policy enforcement.
Place, publisher, year, edition, pages
Umeå: Umeå University, 2026. , p. 56
Series
Report / UMINF, ISSN 0348-0542 ; 26.09
Keywords [en]
Virtual Knowledge Graph/Ontology-Based Data Access, The Intersection of Ground-Atom censors, Policy- Protected Virtual Knowledge Grap, Role Based Acces Control with PPVKG, Break-the-Glass
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:umu:diva-257864ISBN: 978-91-6850-107-9 (print)ISBN: 978-91-6850-108-6 (electronic)OAI: oai:DiVA.org:umu-257864DiVA, id: diva2:2093836
Public defence
2026-09-14, MIT.A.316, MIT-huset, Umeå, 09:00 (English)
Opponent
Supervisors
2026-08-242026-08-202026-08-21Bibliographically approved
List of papers