首页> 外文期刊>EURASIP journal on information security >DB-SECaaS: a cloud-based protection system for document-oriented NoSQL databases
【24h】

DB-SECaaS: a cloud-based protection system for document-oriented NoSQL databases

机译:DB-SECAAS:以文档为导向的NoSQL数据库的基于云保护系统

获取原文
           

摘要

The trend of cloud databases is leaning towards Not Only SQL (NoSQL) databases as they provide better support for scalable storage and quick retrieval of exponentially voluminous data. One of the more prominent types of NoSQL databases is document-based storage, which is being increasingly used in the dynamic cloud paradigm. However, there are inherent security issues in cloud, including remote data residency along with the non-existent control of owners over their own data. In addition to that, the inherent security features of most document-based NoSQL databases lack granular access control and robust confidentiality mechanisms. There is also a distinct lack of a comprehensive solution that effectively caters to all the security requirements of a document-oriented database in cloud. In order to overcome these issues, we propose a database security-as-a-service (DB-SECaaS) system over document-oriented database hosted in cloud, which provides authentication, fine-grained authorization, and encryption of the database objects, while ensuring that access to the data is granted only to authorized users on a need-to-know basis. The paper shows that the DB-SECaaS system strongly enhances the security of document-oriented databases on cloud, and it is thus expected to facilitate the industry to reap the benefits of NoSQL without worrying over security issues. In order to certify the abovementioned security enhancements, provided by DB-SECaaS, the paper also provides a formal analysis of DB-SECaaS using the Scyther model checker. As a proof of concept, the core functionalities of the protocol, i.e., authorization, authentication, and encryption, are formally modeled in Scyther to formally verify that the proposed framework mitigates privacy and security concerns.
机译:云数据库的趋势不仅倾向于SQL(NoSQL)数据库,因为它们提供了更好地支持可伸缩存储和快速检索指数庞大的数据。更突出类型的NoSQL数据库之一是基于文档的存储,其越来越多地用于动态云范例。但是,云中存在固有的安全问题,包括远程数据居住,以及对自己数据的所有者的不存在控制。除此之外,基于大多数文档的NoSQL数据库的固有安全性功能缺少粒度访问控制和强大的机制。还有一个明显缺乏全面的解决方案,有效地迎合了云中的文档导向数据库的所有安全要求。为了克服这些问题,我们提出了一种在云中托管的文档的数据库上的数据库安全 - AS-Service(DB-SECAAS)系统,它提供了身份验证,细粒度授权和数据库对象的加密确保仅授予数据的访问,以便以授权的方式授予授权的用户。论文表明,DB-SECAAS系统强烈增强了云上的文档导向数据库的安全性,因此预期促进该行业从未担心安全问题的情况下获得NoSQL的好处。为了认证由DB-SECAAS提供的上述安全增强功能,本文还使用SCYTHER模型检查器提供DB-SECAAS的正式分析。作为概念证明,协议的核心功能,即授权,身份验证和加密,在SCYTHER中正式建模,以正式验证所提出的框架减轻隐私和安全问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号