A propagation model for provenance views of public/private workflows

Susan B. Davidson*, Tova Milo, Sudeepa Roy

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review


We study the problem of concealing functionality of a proprietary or private module when provenance information is shown over repeated executions of a workflow which contains both public and private modules. Our approach is to use provenance views to hide carefully chosen subsets of data over all executions of the workflow to ensure Γ-privacy: for each private module and each input x, the module's output f(x) is indistinguishable from Γ-1 other possible values given the visible data in the workflow executions. We show that Γ-privacy cannot be achieved simply by combining solutions for individual private modules; data hiding must also be propagated through public modules. We then examine how much additional data must be hidden and when it is safe to stop propagating data hiding. The answer depends strongly on the workflow topology as well as the behavior of public modules on the visible data. In particular, for a class of workflows (which include the common tree and chain workflows), taking private solutions for each private module, augmented with a public closure that is upstream-downstream safe, ensures Γ-privacy. We define these notions formally and show that the restrictions are necessary. We also study the related optimization problems of minimizing the amount of hidden data.

Original languageEnglish
Title of host publicationICDT 2013 - 16th International Conference on Database Theory, Proceedings
PublisherAssociation for Computing Machinery
Number of pages12
ISBN (Print)9781450315982
StatePublished - 2013
Event16th International Conference on Database Theory, ICDT 2013 - Genoa, Italy
Duration: 18 Mar 201322 Mar 2013

Publication series

NameACM International Conference Proceeding Series


Conference16th International Conference on Database Theory, ICDT 2013


FundersFunder number
Seventh Framework Programme291071


    • Optimization
    • Privacy
    • Provenance
    • Workflows


    Dive into the research topics of 'A propagation model for provenance views of public/private workflows'. Together they form a unique fingerprint.

    Cite this