Braun, UriShinnar, Avi2015-11-182006Braun, Uri and Avi Shinnar. 2006. A Security Model for Provenance. Harvard Computer Science Group Technical Report TR-04-06.http://nrs.harvard.edu/urn-3:HUL.InstRepos:23586584Most security models are designed to protect data. Some also deal with traditional metadata. Provenance metadata introduces additional complexity, as does the delicate interactions between provenance metadata and the data it describes. We designed a security model for provenance metadata. Our requirements were derived from potential users. The security model consists of two non-interfering models. One protects the structure or work-flow — namely which ancestors and descendants are accessible to which users. A second model specifies which node attributes are accessible to which users. Our evaluation suggests that our security model meets the users’ requirements.en-USA Security Model for ProvenanceResearch Paper or Report2015-11-18