SDB: A Secure Query Processing System with Data Interoperability

SDB: A Secure Query Processing System with Data Interoperability
复制标题

SDB:具有数据互操作性的安全查询处理系统

DOI:
--
复制
发表时间:
2015
影响因子:
2.5
通讯作者:
Eric Lo
Eric Lo
中科院分区:
计算机科学2区
文献类型:
--
作者:
Zhian He;W. Wong;B. Kao;D. Cheung;Rongbin Li;S. Yiu;Eric Lo

文献摘要

被引文献

相似文献

我们解决了一个云数据库系统中的安全问题,该系统采用DBaaS模型-数据所有者(DO)将数据导出到云数据库服务提供商(SP)。为了提供数据安全性,敏感数据在上传到SP之前由DO加密。与现有的安全查询处理系统(如CryptDB [7]和MONOMI [8])相比,其中数据操作(例如,比较或添加)由专门的加密方案支持,我们的演示系统SDB是基于一组数据互操作的安全运算符实现的,即,一个运算符的输出可以用作另一个运算符的输入。因此,SDB可以支持广泛的复杂查询(例如,所有TPC-H查询)。在这个演示中,我们展示了SDB原型如何在TPC-H等复杂工作负载上支持安全的查询处理。我们还演示了我们的系统如何保护敏感信息免受恶意攻击。
We address security issues in a cloud database system which employs the DBaaS model --- a data owner (DO) exports data to a cloud database service provider (SP). To provide data security, sensitive data is encrypted by the DO before it is uploaded to the SP. Compared to existing secure query processing systems like CryptDB [7] and MONOMI [8], in which data operations (e.g., comparison or addition) are supported by specialized encryption schemes, our demo system, SDB, is implemented based on a set of data-interoperable secure operators, i.e., the output of an operator can be used as input of another operator. As a result, SDB can support a wide range of complex queries (e.g., all TPC-H queries) efficiently. In this demonstration, we show how our SDB prototype supports secure query processing on complex workload like TPC-H. We also demonstrate how our system protects sensitive information from malicious attackers.