• DocumentCode
    2897942
  • Title

    Balancing Security and Performance for Enhancing Data Privacy in Data Warehouses

  • Author

    Santos, Ricardo Jorge ; Bernardino, Jorge ; Vieira, Marco

  • Author_Institution
    CISUC DEI FCTUC, Univ. of Coimbra, Coimbra, Portugal
  • fYear
    2011
  • fDate
    16-18 Nov. 2011
  • Firstpage
    242
  • Lastpage
    249
  • Abstract
    Data Warehouses (DWs) store the golden nuggets of the business, which makes them an appealing target. To ensure data privacy, encryption solutions have been used and proven efficient in their security purpose. However, they introduce massive storage space and performance overheads, making them unfeasible for DWs. We propose a data masking technique for protecting sensitive business data in DWs that balances security strength with database performance, using a formula based on the mathematical modular operator. Our solution manages apparent randomness and distribution of the masked values, while introducing small storage space and query execution time overheads. It also enables a false data injection method for misleading attackers and increasing the overall security strength. It can be easily implemented in any DataBase Management System (DBMS) and transparently used, without changes to application source code. Experimental evaluations using a real-world DW and TPC-H decision support benchmark implemented in leading commercial DBMS Oracle llg and Microsoft SQL Server 2008 demonstrate its overall effectiveness. Results show substantial savings of its implementation costs when compared with state of the art data privacy solutions provided by those DBMS and that it outperforms those solutions in both data querying and insertion of new data.
  • Keywords
    data privacy; data warehouses; DBMS; DW; Microsoft SQL Server 2008; data injection method; data masking technique; data privacy enhancement; data warehouses; database management system; golden nuggets; mathematical modular operator; query execution; storage space; Data privacy; Databases; Encryption; Middleware; Servers; Data encryption; Data masking; Data obfuscation; Data privacy; Data security; Data warehousing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Trust, Security and Privacy in Computing and Communications (TrustCom), 2011 IEEE 10th International Conference on
  • Conference_Location
    Changsha
  • Print_ISBN
    978-1-4577-2135-9
  • Type

    conf

  • DOI
    10.1109/TrustCom.2011.33
  • Filename
    6120825