首页> 外文学位 >Confidentiality and integrity in distributed data exchange.
【24h】

Confidentiality and integrity in distributed data exchange.

机译:分布式数据交换中的机密性和完整性。

获取原文
获取原文并翻译 | 示例

摘要

The distributed exchange of structured data has emerged on the World Wide Web because it promises efficiency, easy collaboration, and---through the integration of diverse data sources---the discovery of new trends and insights. Along with these benefits, however, there is also the danger that exchanged data will be disclosed inappropriately or modified by unauthorized parties. This dissertation provides conceptual and practical tools for ensuring the confidentiality and integrity of data that is exchanged across heterogeneous systems.; Securing data in such settings is challenging because participants may behave maliciously, and because their remote systems are outside the control of the data owner. This dissertation addresses these challenges, first by developing a precise analysis of the information disclosure that may result from publishing relational data. This is a critical prerequisite to forming a policy for permitting or denying access to data. The novel notion of information disclosure presented here can capture leaks that may result from collusion by multiple parties, or from prior knowledge they may possess. This dissertation then addresses the practical problems of safely and efficiently guaranteeing security properties for distributed data. To provide confidentiality, a flexible fine-grained encryption framework is proposed which allows data owners to construct, from a set of access policies, a single encrypted database that can be stored and exchanged by all parties. Access is granted by separately disseminating keys. To provide integrity, an efficient authentication mechanism is described which can be used to detect tampering when data is stored by an untrusted database. Together these techniques can significantly advance the security of distributed data exchange.
机译:结构化数据的分布式交换已出现在万维网上,因为它有望提高效率,简化协作,并且-通过集成各种数据源-发现新趋势和新见解。然而,除了这些好处外,还存在交换的数据将被不当披露或被未授权方修改的危险。本文为确保跨异构系统交换的数据的机密性和完整性提供了概念和实用的工具。在这样的环境中保护数据具有挑战性,因为参与者可能有恶意行为,并且因为他们的远程系统不受数据所有者的控制。本文首先通过对发布关系数据可能导致的信息披露问题进行精确分析来解决这些挑战。这是形成允许或拒绝访问数据的策略的关键前提。这里介绍的新颖的信息披露概念可以捕获由多方合谋或他们可能拥有的先验知识造成的泄漏。然后,本文解决了安全有效地保证分布式数据安全性的实际问题。为了提供机密性,提出了一种灵活的细粒度加密框架,该框架允许数据所有者根据一组访问策略构建可以由各方存储和交换的单个加密数据库。通过单独分发密钥来授予访问权限。为了提供完整性,描述了一种有效的身份验证机制,该机制可用于在数据不受信任的数据库存储时检测篡改。这些技术一起可以大大提高分布式数据交换的安全性。

著录项

  • 作者

    Miklau, Gerome.;

  • 作者单位

    University of Washington.;

  • 授予单位 University of Washington.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2005
  • 页码 143 p.
  • 总页数 143
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号