Transactions on Large-Scale Data- and Knowledge-Centered Systems XXXVII
Transactions on Large-Scale Data- and Knowledge-Centered Systems XXXVII
复制标题
大规模数据和知识中心系统交易 XXXVII
DOI:
--
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
R. Wagner
中科院分区:
文献类型:
--
作者:
R. Wagner
In this paper we address the problem of data confidentiality when outsourcing data to cloud service providers. In our separation of duties approach, the original data set is fragmented into insensitive subsets such that each subset can be managed by an independent cloud provider. Security policies are expressed as sets of confidentiality constraints that induce the fragmentation process. We assume that the different cloud providers do not communicate with each other so that only the actual data owner is able to link the subsets and reconstruct the original data set. While confidentiality is a hard constraint that has to be satisfied in our approach, we consider two further optimization goals (the minimization of the amount of cloud providers and the maximization of utility as defined by visibility constraints) as well as data dependencies that might lead to unwanted disclosure of data. We extend prior work by formally defining the confidentiality and optimization requirements as an optimization problem. We provide an integer linear program (ILP) formulation and analyze different settings of the problem. We present a prototype that exploits a distributed installation of several PostgreSQL database systems; we give an in-depth account of the sophisticated distributed query management that is enforced by defining views for the outsourced data sets and rewriting queries according to the fragments.
影响因子:
3.7
作者:
Belhajjame, Khalid;Paton, Norman W.;Hedeler, Cornelia
通讯作者:
Hedeler, Cornelia