Transactions on Large-Scale Data- and Knowledge-Centered Systems XXXVII

Transactions on Large-Scale Data- and Knowledge-Centered Systems XXXVII
复制标题

大规模数据和知识中心系统交易 XXXVII

DOI:
--
复制
发表时间:
2018
期刊:
Lecture Notes in Computer Science
影响因子:
--
通讯作者:
R. Wagner
R. Wagner
中科院分区:
--
文献类型:
--
作者:
R. Wagner

文献摘要

参考文献

被引文献

相似文献

在本文中,我们解决了数据外包给云服务提供商时的数据保密性问题。在我们的职责分离方法中,原始数据集被分割成不敏感的子集,这样每个子集都可以由独立的云提供商管理。安全策略表示为引发碎片化过程的机密性约束集。我们假设不同的云提供商不相互通信,因此只有实际的数据所有者能够链接子集并重建原始数据集。虽然机密性是我们的方法中必须满足的硬约束,但我们考虑了两个进一步的优化目标(云提供商数量的最小化和由可见性约束定义的效用最大化)以及可能导致不必要的数据披露的数据依赖关系。我们通过将保密性和优化需求正式定义为优化问题来扩展先前的工作。我们提供了一个整数线性规划(ILP)公式,并分析了问题的不同设置。我们提出了一个原型,利用几个PostgreSQL数据库系统的分布式安装;我们深入介绍了复杂的分布式查询管理,它通过为外包数据集定义视图和根据片段重写查询来实现。
In this paper we address the problem of data confidentiality when outsourcing data to cloud service providers. In our separation of duties approach, the original data set is fragmented into insensitive subsets such that each subset can be managed by an independent cloud provider. Security policies are expressed as sets of confidentiality constraints that induce the fragmentation process. We assume that the different cloud providers do not communicate with each other so that only the actual data owner is able to link the subsets and reconstruct the original data set. While confidentiality is a hard constraint that has to be satisfied in our approach, we consider two further optimization goals (the minimization of the amount of cloud providers and the maximization of utility as defined by visibility constraints) as well as data dependencies that might lead to unwanted disclosure of data. We extend prior work by formally defining the confidentiality and optimization requirements as an optimization problem. We provide an integer linear program (ILP) formulation and analyze different settings of the problem. We present a prototype that exploits a distributed installation of several PostgreSQL database systems; we give an in-depth account of the sophisticated distributed query management that is enforced by defining views for the outsourced data sets and rewriting queries according to the fragments.
DOI: 10.1016/j.is.2013.01.006
发表时间: 2013-07-01
影响因子: 3.7
作者:
Belhajjame, Khalid;Paton, Norman W.;Hedeler, Cornelia
通讯作者: Hedeler, Cornelia