DocumentCode :
3123329
Title :
Separating Authentication from Query Execution in Outsourced Databases
Author :
Papadopoulos, Stavros ; Papadias, Dimitris ; Cheng, Weiwei ; Tan, Kian-Lee
Author_Institution :
Hong Kong Univ. of Sci. & Technol., Hong Kong
fYear :
2009
fDate :
March 29 2009-April 2 2009
Firstpage :
1148
Lastpage :
1151
Abstract :
In the database outsourcing paradigm, a data owner (DO) delegates its DBMS administration to a specialized service provider (SP) that receives and processes queries from clients. The traditional outsourcing model (TOM) requires that the DO and the SP maintain authenticated data structures to enable authentication of query results. In this paper, we present SAE, a novel outsourcing model that separates authentication from query execution. Specifically, the DO does not perform any task except for maintaining its dataset (if there are updates). The SP only stores the DO´s dataset and computes the query results using a conventional DBMS. All security-related tasks are outsourced to a separate trusted entity (TE), which maintains limited authentication information about the original dataset. A client contacts the TE when it wishes to establish the correctness of a result returned by the SP. The TE efficiently generates a verification token of negligible size. The client can verify the token with minimal cost. SAE eliminates the participation of the DO and the SP in the authentication process, and outperforms TOM in every aspect, including processing cost for all parties involved, communication overhead, query response time and ease of implementation in practical applications.
Keywords :
database management systems; message authentication; outsourcing; query processing; tree data structures; DBMS administration; authentication; data owner; database outsourcing; query execution; query processing; service provider; tree data structure; trusted entity; Authentication; Costs; Data engineering; Data security; Data structures; Databases; Delay; Outsourcing; Public key cryptography; Tellurium; Authenticated Query Processing; Database Outsourcing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Data Engineering, 2009. ICDE '09. IEEE 25th International Conference on
Conference_Location :
Shanghai
ISSN :
1084-4627
Print_ISBN :
978-1-4244-3422-0
Electronic_ISBN :
1084-4627
Type :
conf
DOI :
10.1109/ICDE.2009.187
Filename :
4812487
Link To Document :
بازگشت