返回
CryptDICE: Distributed data protection system for secure cloud data storage and computation
DOI:10.1016/j.is.2020.101671.png)
摘要
En 中文
Cloud storage allows organizations to store data at remote sites of service providers. Although cloud storage services offer numerous benefits, they also involve new risks and challenges with respect to data security and privacy aspects. To preserve confidentiality, data must be encrypted before outsourcing to the cloud. Although this approach protects the security and privacy aspects of data, it also impedes regular functionality such as executing queries and performing analytical computations. To address this concern, specific data encryption schemes (e.g., deterministic, random, homomorphic, order-preserving, etc.) can be adopted that still support the execution of different types of queries (e.g., equality search, full-text search, etc.) over encrypted data. However, these specialized data encryption schemes have to be implemented and integrated in the application and their adoption introduces an extra layer of complexity in the application code. Moreover, as these schemes imply trade-offs between performance and security, storage efficiency, etc, making the appropriate trade-off is a challenging and non-trivial task. In addition, to support aggregate queries, User Defined Functions (UDF) have to be implemented directly in the database engine and these implementations are specific to each underlying data storage technology, which demands expert knowledge and in turn increases management complexity. In this paper, we introduce CryptDICE, a distributed data protection system that (i) provides builtin support for a number of different data encryption schemes, made accessible via annotations that represent application-specific (search) requirements; (ii) supports making appropriate trade-offs and execution of these encryption decisions at diverse levels of data granularity; and (iii) integrates a lightweight service that performs dynamic deployment of User Defined Functions (UDF) -without performing any alteration directly in the database engine- for heterogeneous NoSQL databases in order to realize low-latency aggregate queries and also to avoid expensive data shuffling (from the cloud to an on-premise data center). We have validated CryptDICE in the context of a realistic industrial SaaS application and carried out an extensive functional validation, which shows the applicability of the middleware platform. In addition, our experimental evaluation efforts confirm that the performance overhead of CryptDICE is acceptable and validates the performance optimizations for achieving low-latency aggregate queries. (C) 2020 Elsevier Ltd. All rights reserved.
Keyword:
Data security and privacy
NoSQL databases
Search over encrypted data
Database-as-a-Service
Data encryption
Cloud computing
Query processing
Computation over encrypted data
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
3.9
论文数:
2.8K
被引数:
1.8K
机构
引用论文
Male and Female Differences in Elite Political Participation: An Examination of the Effects of Socioeconomic and Familial Variables男女在精英政治参与中的差异:社会经济和家族变量影响的研究
Parental Investment and Elite Family Structure in Preindustrial States: A Case Study of Late Medieval‐Early Modern Portuguese Genealogies工业化前国家的父母投资和精英家庭结构: 中世纪晚期-早期现代葡萄牙家谱的案例研究
Remembering to execute deferred tasks in simulated air traffic control: The impact of interruptions.

