Using Boolean reasoning to anonymize databases

被引:41
作者
Ohrn, A [1 ]
Ohno-Machado, L
机构
[1] Norwegian Univ Sci & Technol, Dept Comp & Informat Sci, Knowledge Syst Grp, N-7034 Trondheim, Norway
[2] Harvard Univ, Brigham & Womens Hosp, Sch Med, Dept Radiol,Decis Syst Grp, Boston, MA 02215 USA
基金
美国国家卫生研究院;
关键词
Boolean reasoning; cell suppression; disclosure control; confidentiality;
D O I
10.1016/S0933-3657(98)00056-6
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper investigates how Boolean reasoning can be used to make the records in a database anonymous. In a medical setting, this is of particular interest due to privacy issues and to prevent the possible misuse of confidential information. As electronic medical records and medical data repositories get more common and widespread, the issue of making sensitive data anonymous becomes increasingly important. A theoretically well-founded algorithm is proposed that via cell suppression can be used to make a database anonymous before releasing or sharing it to the outside world. The degree of anonymity can be tailored according to the specific needs of the recipient, and according to the amount of trust we place in the recipient. Furthermore, the required measure of anonymity can be specified as far down as to the individual objects in the database. The algorithm can also be used for anonymization relative to a particular piece of information, effectively blocking deterministic inferences about sensitive database fields. (C) 1994 Elsevier Science B.V. All rights reserved.
引用
收藏
页码:235 / 254
页数:20
相关论文
共 11 条
[1]  
[Anonymous], 1996, P 3 INT SEM STAT CON
[2]  
Brown F.M., 1990, Boolean Reasoning: The Logic of Boolean Equations
[3]  
CLAYTON P, 1997, RECORD PROTECTING EL
[4]  
FIENBERG SE, 1997, 668 CARN MELL U DEP
[5]  
OHRN A, 1998, ROUGH SETS KNOWLEDGE
[6]  
Pawlak Z., 1991, Rough sets: Theoretical aspects of reasoning about data, V9, DOI DOI 10.1007/978-94-011-3534-4
[7]  
SKOWRON A, 1995, FR ART INT, V28, P220
[8]  
Skowron A., 1992, INTELLIGENT DECISION, P331, DOI DOI 10.1007/978-94-015-7975-9_21
[9]  
Sweeney L, 1997, J AM MED INFORM ASSN, P51
[10]  
SWEENEY L, 1998, DATABASE SECURITY, V11