Prometheus: Privacy-aware data retrieval on hybrid cloud

Prometheus: Privacy-aware data retrieval on hybrid cloud
复制标题

DOI:
10.1109/infcom.2013.6567072
复制
发表时间:
2013-04
期刊:
2013 Proceedings IEEE INFOCOM
影响因子:
--
通讯作者:
Zhigang Zhou;Hongli Zhang;Xiaojiang Du;Panpan Li;Xiangzhan Yu
Zhigang Zhou;Hongli Zhang;Xiaojiang Du;Panpan Li;Xiangzhan Yu
中科院分区:
其他
文献类型:
--
作者:
Zhigang Zhou;Hongli Zhang;Xiaojiang Du;Panpan Li;Xiangzhan Yu

文献摘要

被引文献

相似文献

随着云计算的到来,数据所有者有动力将他们的数据外包到云平台,以获得极大的灵活性和经济节约。然而,数据隐私问题阻碍了这一发展:数据所有者可能拥有隐私数据,并且数据不能直接外包到云中。以前的解决方案主要使用加密。然而,加密给搜索、查询等其他数据操作带来了很大的不便和较大的开销。为了应对这一挑战,我们采用了混合云。在本文中,我们提出了一套新的技术来有效地进行隐私感知数据检索。基本思想是拆分数据,将敏感数据保存在受信任的私有云中,同时将不敏感的数据移动到公共云。然而,目前的框架并不支持混合云上的隐私感知数据检索。数据所有者必须手动拆分数据。我们的系统名为Prometheus,采用流行的MapReduce框架,并使用独立于具体应用的数据划分策略。普罗米修斯可以自动将敏感信息与公共数据分开。我们正式证明了普罗米修斯的隐私保护功能。我们还表明,除了半诚实的云模型之外,我们的方案还可以防御恶意的云模型。我们在Hadoop上实现了Prometheus,并在大型云测试床上使用真实数据集对其性能进行了评估。大量的实验证明了该方案的有效性和实用性。
With the advent of cloud computing, data owner is motivated to outsource their data to the cloud platform for great flexibility and economic savings. However, the development is hampered by data privacy concerns: Data owner may have privacy data and the data cannot be outsourced to cloud directly. Previous solutions mainly use encryption. However, encryption causes a lot of inconveniences and large overheads for other data operations, such as search and query. To address the challenge, we adopt hybrid cloud. In this paper, we present a suit of novel techniques for efficient privacy-aware data retrieval. The basic idea is to split data, keeping sensitive data in trusted private cloud while moving insensitive data to public cloud. However, privacy-aware data retrieval on hybrid cloud is not supported by current frameworks. Data owners have to split data manually. Our system, called Prometheus, adopts the popular MapReduce framework, and uses data partition strategy independent to specific applications. Prometheus can automatically separate sensitive information from public data. We formally prove the privacy-preserving feature of Prometheus. We also show that our scheme can defend against the malicious cloud model, in addition to the semi-honest cloud model. We implement Prometheus on Hadoop and evaluate its performance using real data set on a large-scale cloud test-bed. Our extensive experiments demonstrate the validity and practicality of the proposed scheme.