首页> 外文学位 >Distributed authorization in loosely coupled data federation .
【24h】

Distributed authorization in loosely coupled data federation .

机译:松散耦合数据联合中的分布式授权。

获取原文
获取原文并翻译 | 示例

摘要

The underlying data model of many integrated information systems is a collection of inter-operable and autonomous database systems, namely, a loosely coupled data federation. A challenging security issue in designing such a data federation is to ensure the integrity and confidentiality of data stored in remote databases through distributed authorization of users. Existing solutions in centralized databases are not directly applicable here due to the lack of a centralized authority, and most solutions designed for outsourced databases cannot easily support frequent updates essential to a data federation. In this thesis, we provide a solution in three steps. First, we devise an architecture to support fully distributed, fine-grained, and data-dependent authorization in loosely coupled data federations. For this purpose, we adapt the integrity-lock architecture originally designed for multilevel secure databases to data federations. Second, we propose an integrity mechanism to detect, localize, and verify updates of data stored in remote databases while reducing communication overhead and limiting the impact of unauthorized updates. We realize the mechanism as a three-stage procedure based on a grid of Merkle Hash Trees built on relational tables. Third, we present a confidentiality mechanism to control remote users' accesses to sensitive data while allowing authorization policies to be frequently updated. We achieve this objective through a new over-encryption scheme based on secret sharing. Finally, we evaluate the proposed architecture and mechanisms through experiments.;
机译:许多集成信息系统的基础数据模型是互操作和自治数据库系统的集合,即松散耦合的数据联合。设计这样的数据联合会中一个具有挑战性的安全问题是通过用户的分布式授权来确保存储在远程数据库中的数据的完整性和机密性。集中式数据库中的现有解决方案由于缺乏集中式权限而不能在此处直接应用,并且大多数为外包数据库设计的解决方案都无法轻松地支持数据联合所必需的频繁更新。在本文中,我们分三个步骤提供了一种解决方案。首先,我们设计一种体系结构,以在松散耦合的数据联合中支持完全分布式,细粒度且与数据相关的授权。为此,我们将最初为多级安全数据库设计的完整性锁体系结构调整为适用于数据联合。其次,我们提出一种完整性机制,用于检测,本地化和验证存储在远程数据库中的数据更新,同时减少通信开销并限制未经授权的更新的影响。我们基于建立在关系表上的Merkle哈希树网格,将机制实现为一个三阶段过程。第三,我们提出一种机密性机制,以控制远程用户对敏感数据的访问,同时允许频繁更新授权策略。我们通过基于秘密共享的新的过度加密方案来实现此目标。最后,我们通过实验评估提出的体系结构和机制。

著录项

  • 作者

    Li, Wei.;

  • 作者单位

    Concordia University (Canada).;

  • 授予单位 Concordia University (Canada).;
  • 学科 Engineering Computer.
  • 学位 M.A.Sc.
  • 年度 2009
  • 页码 65 p.
  • 总页数 65
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号