首页> 外文期刊>Distributed and Parallel Databases >Access control aware data retrieval for secret sharing based database outsourcing
【24h】

Access control aware data retrieval for secret sharing based database outsourcing

机译:基于访问控制的数据检索,用于基于秘密共享的数据库外包

获取原文
获取原文并翻译 | 示例
           

摘要

Enforcing dynamic and confidential access control policies is a challenging issue of data outsourcing to external servers due to the lack of trust towards the servers. In this paper, we propose a scalable yet flexible access control enforcement mechanism when the underlying relational data, on which access policies are defined, has been shared through a secret sharing scheme. For sharing values of an attribute in a relation, the attribute is assigned a secret distribution key and its values are split and distributed among data servers according to a Shamir based secret sharing scheme. Given access control policies over attributes of the relation schema, access to distribution keys, used further for reconstructing original values, is managed using the Chinese remainder theorem. Our solution, in addition to preserving the confidentiality of access control policies, is flexible to efficiently adopt grant and revoke of authorizations. Moreover, it prevents the possibility of information leakage caused by query processing through an access control aware retrieval of data shares. That is, our solution not only enforces access control policies for reconstructing shares and obtaining original values, but also for retrieving shares in query processing scenario. We implemented our mechanism and performed extensive experiments, whose results confirm its efficiency and considerable scalability in practice.
机译:由于缺乏对服务器的信任,因此执行动态和机密的访问控制策略是将数据外包给外部服务器的一个具有挑战性的问题。在本文中,当通过秘密共享方案共享了定义访问策略的基础关系数据时,我们提出了一种可伸缩但灵活的访问控制实施机制。为了在关系中共享属性的值,该属性被分配了秘密分发密钥,并且根据基于Shamir的秘密共享方案在数据服务器之间拆分和分发了其值。给定对关系模式的属性的访问控制策略,将使用中文余数定理来管理对分配键的访问,这些键进一步用于重建原始值。我们的解决方案除了保留访问控制策略的机密性外,还可以灵活地有效采用授权和撤销授权。此外,通过访问控制感知的数据共享检索,可以防止由于查询处理而导致信息泄漏的可能性。也就是说,我们的解决方案不仅实施访问控制策略以重建共享并获取原始值,而且还可以在查询处理场景中获取共享。我们实施了该机制并进行了广泛的实验,其结果证实了其效率和在实践中的可扩展性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号