A fine-grained access control model for key-value systems

In this paper we present K-VAC -- a key-value access control model for modern non-relational data stores. This model supports specification and enforcement of access control policies at different levels of resource hierarchy, such as a column family, a row, or a column. The policies can be based on contents of the key-value store and they may also include context information. Through a case-study example we demonstrate the capabilities of this system.