Immutable Authentication and Integrity Schemes for Outsourced Databases

Immutable Authentication and Integrity Schemes for Outsourced Databases
复制标题

DOI:
10.1109/tdsc.2016.2530708
复制
发表时间:
2018
影响因子:
7.3
通讯作者:
A. Yavuz
A. Yavuz
中科院分区:
计算机科学2区
文献类型:
--
作者:
A. Yavuz

文献摘要

被引文献

相似文献

数据库外包使组织能够将其数据管理开销转移给外部服务提供商。不可变签名是为这类应用程序提供身份验证和完整性的理想工具,它具有一种称为不可变性的重要属性。签名的不变性确保了攻击者不能从先前的查询及其对应的签名中为未提出的查询推导出有效的签名。这可防止攻击者通过此类派生签名创建自己的事实上的服务。遗憾的是,现有的不可变签名的计算/通信代价非常高,这使得它们不适用于现实生活中的应用。在本文中,我们开发了三个新的方案,称为实用和不变签名花束(${PISB}$),它们实现了外包数据库的高效不变性。${PISB}$方案简单、非交互且计算/通信效率高。我们的通用方案可以由任何结合标准签名的聚合签名来构造。我们的具体方案是由浓缩RSA和顺序聚合RSA构造的。它具有较低的验证者计算开销和紧凑的签名。我们的第三个方案提供了现有方案中最低的端到端延迟,它实现了高效的签名预计算能力。对随机Oracle模型下的${PISB}$方案进行了形式化的安全性分析,并从理论上分析了签名的不变性与签名提取的关系。我们还证明了${PISB}$方案比以前的备选方案更有效。
Database outsourcing enables organizations to offload their data management overhead to the external service providers. Immutable signatures are ideal tools to provide authentication and integrity for such applications with an important property called immutability. Signature immutability ensures that, no attacker can derive a valid signature for unposed queries from previous queries and their corresponding signatures. This prevents an attacker from creating his own de-facto services via such derived signatures. Unfortunately, existing immutable signatures are very computation/communication costly, which make them impractical for real-life applications. In this paper, we developed three new schemes called practical and immutable signature bouquets ( ${PISB}$), which achieve efficient immutability for outsourced databases. ${PISB}$ schemes are simple, non-interactive, and computation/communication efficient. Our generic scheme can be constructed from any aggregate signature coupled with a standard signature. Our specific scheme is constructed from Condensed-RSA and Sequential Aggregate RSA. It has a low verifier computational overhead and compact signature. Our third scheme offers the lowest end-to-end delay among existing alternatives by enabling efficient signature pre-computability. We provide formal security analysis of ${PISB}$ schemes (in Random Oracle Model) and give a theoretical analysis on the relationship between signature immutability and signature extraction. We also showed that ${PISB}$ schemes are more efficient than previous alternatives.