Author Login Editor-in-Chief Peer Review Editor Work Office Work

Computer Engineering ›› 2011, Vol. 37 ›› Issue (9): 173-175. doi: 10.3969/j.issn.1000-3428.2011.09.060

• Networks and Communications • Previous Articles     Next Articles

Security Access Control Mechanism of Outsourced Database

MA Hao, WANG Xiao-ming   

  1. (Department of Computer, Jinan University, Guangzhou 510632, China)
  • Online:2011-05-05 Published:2011-05-12

外包数据库的安全访问控制机制

麻 浩,王晓明   

  1. (暨南大学计算机系,广州 510632)
  • 作者简介:麻 浩(1985-),男,硕士研究生,主研方向:网络信息,数据库安全;王晓明,教授、博士
  • 基金资助:
    国家自然科学基金资助项目(61070164);广东省自然科学基金资助项目(8151063201000022);广东省科技计划基金资助项目(2010B010600025)

Abstract: Through the analysis of outsourced database two layer encryption scheme, its security flaw is pointed out , that is, authorized users can easy authorized other non-authorized user to access to resource. An improved scheme that can derive the encryption key by using linear equation in two unknowns is proposed. To adapt to access policy changes avoiding re-encryption for the data owner, this scheme exploits a two layer encryption scheme to prevent non-authorized users to access resource. Analysis shows that this scheme not only can overcome the flaws of the original program but also adapt to dynamic changes. It is a safe and efficient access control scheme.

Key words: outsourced database, access control, data encryption, key management, privacy preservation

摘要: 通过对外包数据库双层加密方案的分析,指出存在授权用户可以将资源访问授权给其他非授权用户的安全缺陷,为此,提出一个改进的安全外包数据访问控制方案。该方案利用二元一次函数诱导产生加密密钥。为适应访问控制策略动态变化,防止非授权用户访问资源,通过双重加密实现授权访问动态变化。分析结果表明,改进方案能够克服外包数据库双层加密方案的安全缺陷,可实现策略动态更新,是一个安全高效的访问控制方案。

关键词: 外包数据库, 访问控制, 数据加密, 密钥管理, 隐私保护

CLC Number: