CryptDICE: Distributed data protection system for secure cloud data storage and computation. Issue 96 (February 2021)
- Record Type:
- Journal Article
- Title:
- CryptDICE: Distributed data protection system for secure cloud data storage and computation. Issue 96 (February 2021)
- Main Title:
- CryptDICE: Distributed data protection system for secure cloud data storage and computation
- Authors:
- Rafique, Ansar
Van Landuyt, Dimitri
Heydari Beni, Emad
Lagaisse, Bert
Joosen, Wouter - Abstract:
- Abstract: Cloud storage allows organizations to store data at remote sites of service providers. Although cloud storage services offer numerous benefits, they also involve new risks and challenges with respect to data security and privacy aspects. To preserve confidentiality, data must be encrypted before outsourcing to the cloud. Although this approach protects the security and privacy aspects of data, it also impedes regular functionality such as executing queries and performing analytical computations. To address this concern, specific data encryption schemes (e.g., deterministic, random, homomorphic, order-preserving, etc.) can be adopted that still support the execution of different types of queries (e.g., equality search, full-text search, etc.) over encrypted data. However, these specialized data encryption schemes have to be implemented and integrated in the application and their adoption introduces an extra layer of complexity in the application code. Moreover, as these schemes imply trade-offs between performance and security, storage efficiency, etc, making the appropriate trade-off is a challenging and non-trivial task. In addition, to support aggregate queries, User Defined Functions (UDF) have to be implemented directly in the database engine and these implementations are specific to each underlying data storage technology, which demands expert knowledge and in turn increases management complexity. In this paper, we introduce CryptDICE, a distributed dataAbstract: Cloud storage allows organizations to store data at remote sites of service providers. Although cloud storage services offer numerous benefits, they also involve new risks and challenges with respect to data security and privacy aspects. To preserve confidentiality, data must be encrypted before outsourcing to the cloud. Although this approach protects the security and privacy aspects of data, it also impedes regular functionality such as executing queries and performing analytical computations. To address this concern, specific data encryption schemes (e.g., deterministic, random, homomorphic, order-preserving, etc.) can be adopted that still support the execution of different types of queries (e.g., equality search, full-text search, etc.) over encrypted data. However, these specialized data encryption schemes have to be implemented and integrated in the application and their adoption introduces an extra layer of complexity in the application code. Moreover, as these schemes imply trade-offs between performance and security, storage efficiency, etc, making the appropriate trade-off is a challenging and non-trivial task. In addition, to support aggregate queries, User Defined Functions (UDF) have to be implemented directly in the database engine and these implementations are specific to each underlying data storage technology, which demands expert knowledge and in turn increases management complexity. In this paper, we introduce CryptDICE, a distributed data protection system that (i) provides built-in support for a number of different data encryption schemes, made accessible via annotations that represent application-specific (search) requirements; (ii) supports making appropriate trade-offs and execution of these encryption decisions at diverse levels of data granularity; and (iii) integrates a lightweight service that performs dynamic deployment of User Defined Functions (UDF) –without performing any alteration directly in the database engine– for heterogeneous NoSQL databases in order to realize low-latency aggregate queries and also to avoid expensive data shuffling (from the cloud to an on-premise data center). We have validated CryptDICE in the context of a realistic industrial SaaS application and carried out an extensive functional validation, which shows the applicability of the middleware platform. In addition, our experimental evaluation efforts confirm that the performance overhead of CryptDICE is acceptable and validates the performance optimizations for achieving low-latency aggregate queries. Highlights: Outsourcing data to third-party cloud providers offers numerous benefits. Data protection support in NoSQL databases is lacking. Executing different types of queries and performing complex computation over encrypted data in NoSQL databases introduces complexity. Performing complex computation next to the database engine to realize low-latency aggregate queries requires large development efforts. A flexible and distributed data protection system, named CryptDICE, is designed. … (more)
- Is Part Of:
- Information systems. Issue 96(2021)
- Journal:
- Information systems
- Issue:
- Issue 96(2021)
- Issue Display:
- Volume 96, Issue 96 (2021)
- Year:
- 2021
- Volume:
- 96
- Issue:
- 96
- Issue Sort Value:
- 2021-0096-0096-0000
- Page Start:
- Page End:
- Publication Date:
- 2021-02
- Subjects:
- Data security and privacy -- NoSQL databases -- Search over encrypted data -- Database-as-a-Service -- Data encryption -- Cloud computing -- Query processing -- Computation over encrypted data
Database management -- Periodicals
Electronic data processing -- Periodicals
Bases de données -- Gestion -- Périodiques
Informatique -- Périodiques
Database management
Electronic data processing
Periodicals
005.7 - Journal URLs:
- http://www.sciencedirect.com/science/journal/03064379 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.is.2020.101671 ↗
- Languages:
- English
- ISSNs:
- 0306-4379
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4496.367300
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 15001.xml