首页> 外文期刊>IEEE Transactions on Knowledge and Data Engineering >ConcurDB: Concurrent Query Authentication for Outsourced Databases
【24h】

ConcurDB: Concurrent Query Authentication for Outsourced Databases

机译:conculdb:外包数据库的并发查询身份验证

获取原文
获取原文并翻译 | 示例
       

摘要

Clients of outsourced databases need Query Authentication (QA) guaranteeing the integrity and authenticity of query results returned by potentially compromised providers. Prior work provides QA assurances for a limited class of queries by deploying several software-based cryptographic constructs. The constructs are often designed assuming read-only or infrequently updated databases. For dynamic datasets, the data owner is required to perform all updates on behalf of clients. Hence, for concurrent updates by multiple clients, such as for OLTP workloads, existing QA solutions are inefficient. We present ConcurDB, a concurrent QA scheme that enables simultaneous updates by multiple clients. To realize concurrent QA, we have designed several new mechanisms. First, we identify and use an important relationship between QA and memory checking to decouple query execution and verification. We allow clients to execute transactions concurrently and perform verifications in parallel using an offline memory checking based protocol. Then, to extend QA to a multi-client scenario, we design new protocols that enable clients to securely exchange a small set of authentication data even when using the untrusted provider as a communication hub. Finally, we overcome provider-side replay attacks. Using ConcurDB, we provide and evaluate concurrent QA for the full TPC-C benchmark. For updates, ConcurDB shows a 4x performance increase over existing solutions.
机译:外包数据库的客户端需要查询身份验证(QA)保证潜在受损提供者返回的查询结果的完整性和真实性。通过部署几个基于软件的加密构造,之前的工作为有限类查询提供了QA保证。构造通常是假设只读或不经常更新的数据库设计。对于动态数据集,需要代表客户端执行所有更新。因此,对于多个客户端的并发更新,例如OLTP工作负载,现有的QA解决方案效率低下。我们呈现ConcuRDB,一种并发QA方案,可以通过多个客户端同时更新。为了实现并发QA,我们设计了几种新机制。首先,我们识别并使用QA和内存检查之间的重要关系来解耦查询执行和验证。我们允许客户端同时执行交易,并使用基于脱机内存检查的协议并行执行验证。然后,将QA扩展到多客户方案,我们设计新的协议,即使在使用不可信的提供商作为通信集线器时,也能使客户端能够安全地交换一小组身份验证数据。最后,我们克服了提供者端重播攻击。使用ConcuLDB,我们为全TPC-C基准提供并进行并发QA。对于更新,ConculdB显示了对现有解决方案的4倍性能增加。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号