arrow
返回

CryptDICE: Distributed data protection system for secure cloud data storage and computation

delete2021-02-01
delete17
PRE
AI
A
Ansar Rafique *
D
Dimitri Van Landuyt
E
Emad Heydari Beni
B
Bert Lagaisse
W
Wouter Joosen
DOI:10.1016/j.is.2020.101671delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Cloud storage allows organizations to store data at remote sites of service providers. Although cloud storage services offer numerous benefits, they also involve new risks and challenges with respect to data security and privacy aspects. To preserve confidentiality, data must be encrypted before outsourcing to the cloud. Although this approach protects the security and privacy aspects of data, it also impedes regular functionality such as executing queries and performing analytical computations. To address this concern, specific data encryption schemes (e.g., deterministic, random, homomorphic, order-preserving, etc.) can be adopted that still support the execution of different types of queries (e.g., equality search, full-text search, etc.) over encrypted data. However, these specialized data encryption schemes have to be implemented and integrated in the application and their adoption introduces an extra layer of complexity in the application code. Moreover, as these schemes imply trade-offs between performance and security, storage efficiency, etc, making the appropriate trade-off is a challenging and non-trivial task. In addition, to support aggregate queries, User Defined Functions (UDF) have to be implemented directly in the database engine and these implementations are specific to each underlying data storage technology, which demands expert knowledge and in turn increases management complexity. In this paper, we introduce CryptDICE, a distributed data protection system that (i) provides builtin support for a number of different data encryption schemes, made accessible via annotations that represent application-specific (search) requirements; (ii) supports making appropriate trade-offs and execution of these encryption decisions at diverse levels of data granularity; and (iii) integrates a lightweight service that performs dynamic deployment of User Defined Functions (UDF) -without performing any alteration directly in the database engine- for heterogeneous NoSQL databases in order to realize low-latency aggregate queries and also to avoid expensive data shuffling (from the cloud to an on-premise data center). We have validated CryptDICE in the context of a realistic industrial SaaS application and carried out an extensive functional validation, which shows the applicability of the middleware platform. In addition, our experimental evaluation efforts confirm that the performance overhead of CryptDICE is acceptable and validates the performance optimizations for achieving low-latency aggregate queries. (C) 2020 Elsevier Ltd. All rights reserved.
Keyword:
Data security and privacy
NoSQL databases
Search over encrypted data
Database-as-a-Service
Data encryption
Cloud computing
Query processing
Computation over encrypted data
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Enterprise Information Systems 封面图
Enterprise Information Systems
IF:
3.9
论文数:
2.8K
被引数:
1.8K

机构

K
KU Leuven
学者数:
5.7W
论文数: 5.2W
被引数: 8.1W
引用论文

引用论文

LARYNGECTOMY
err1974-06-01
err0
PREAI
err&NA;
err分享
err收藏
Dimensional characterization of selected elements in airborne PM10 samples using μ‐SRXRF
err2011-11-11
err0
PREAI
errF. Cozzi; G. Gržinić; S. Cozzutto; P. Barbieri; M. Bovenzi; G. Adami
err分享
err收藏
Training for strategy in visual search
err1997-08-01
err0
PREAI
errMao-Jiun J. Wang; Shu-Chiang Lin; Colin G. Drury
err分享
err收藏
err分享
err收藏
err分享
err收藏
学者 查看更多内容