首页> 外文OA文献 >Hierarchical Role-Based Access Control with Homomorphic Encryption for Database as a Service
【2h】

Hierarchical Role-Based Access Control with Homomorphic Encryption for Database as a Service

机译:基于角色的分层访问控制与同态加密   数据库即服务

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Database as a service provides services for accessing and managing customersdata which provides ease of access, and the cost is less for these services.There is a possibility that the DBaaS service provider may not be trusted, anddata may be stored on untrusted server. The access control mechanism canrestrict users from unauthorized access, but in cloud environment accesscontrol policies are more flexible. However, an attacker can gather sensitiveinformation for a malicious purpose by abusing the privileges as another userand so database security is compromised. The other problems associated with theDBaaS are to manage role hierarchy and secure session management for querytransaction in the database. In this paper, a role-based access control for themultitenant database with role hierarchy is proposed. The query is granted withleast access privileges, and a session key is used for session management. Theproposed work protects data from privilege escalation and SQL injection. Ituses the partial homomorphic encryption (Paillier Encryption) for theencrypting the sensitive data. If a query is to perform any operation onsensitive data, then extra permissions are required for accessing sensitivedata. Data confidentiality and integrity are achieved using the role-basedaccess control with partial homomorphic encryption.
机译:数据库即服务提供了用于访问和管理客户数据的服务,这提供了访问的便捷性,并且这些服务的成本更低。DBaaS服务提供者可能不受信任,并且数据可能存储在不受信任的服务器上。访问控制机制可以限制用户进行未经授权的访问,但是在云环境中,访问控制策略更加灵活。但是,攻击者可以通过滥用另一用户的特权来收集恶意信息,以达到恶意目的,从而危及数据库的安全性。与DBaaS相关的其他问题是管理角色层次结构和对数据库中的查询事务进行安全的会话管理。提出了一种基于角色的多租户数据库角色访问控制方法。该查询被授予最低访问权限,并且会话密钥用于会话管理。提议的工作可以保护数据免受特权升级和SQL注入的侵害。它使用部分同态加密(Paillier加密)来加密敏感数据。如果查询要对敏感数据执行任何操作,则访问敏感数据需要额外的权限。使用具有部分同态加密的基于角色的访问控制,可以实现数据的机密性和完整性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号