An authorization model for query execution in the cloud

被引:1
|
作者
di Vimercati, Sabrina De Capitani [1 ]
Foresti, Sara [1 ]
Jajodia, Sushil [2 ]
Livraga, Giovanni [1 ]
Paraboschi, Stefano [3 ]
Samarati, Pierangela [1 ]
机构
[1] Univ Milan, Milan, Italy
[2] George Mason Univ, Fairfax, VA 22030 USA
[3] Univ Bergamo, Bergamo, Italy
来源
VLDB JOURNAL | 2022年 / 31卷 / 03期
基金
欧盟地平线“2020”; 美国国家科学基金会;
关键词
Authorization model; Collaborative query evaluation; Plaintext and encrypted visibility; Implicit attributes; Equivalent attributes; Relation profile;
D O I
10.1007/s00778-021-00709-x
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We present a novel approach for the specification and enforcement of authorizations that enables controlled data sharing for collaborative queries in the cloud. Data authorities can establish authorizations regulating access to their data distinguishing three visibility levels (no visibility, encrypted visibility, and plaintext visibility). Authorizations are enforced accounting for the information content carried in the computation to ensure no information is improperly leaked and adjusting visibility of data on-the-fly. Assignment of operations to subjects takes into consideration the cost of operation execution as well as of the encryption/decryption operations needed to make the assignment authorized. Our approach enables users and data authorities to fully enjoy the benefits and economic savings of the competitive open cloud market, while maintaining control over data.
引用
收藏
页码:555 / 579
页数:25
相关论文
共 50 条
  • [21] Highly Scalable Model for Tests Execution in Cloud Environments
    Gopularam, Bhanu Prakash
    Yogeesha, C. B.
    Periasamy, Prabhu
    2012 18TH ANNUAL INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING AND COMMUNICATIONS (ADCOM), 2012, : 54 - 58
  • [22] Fuzzy Authorization for Cloud Storage
    Zhu, Shasha
    Gong, Guang
    IEEE TRANSACTIONS ON CLOUD COMPUTING, 2014, 2 (04) : 422 - 435
  • [23] Authorization as a Service in Cloud Environments
    Alsubaih, Amal
    Hafez, Alaaeldin
    Alghathbar, Khaled
    2013 IEEE THIRD INTERNATIONAL CONFERENCE ON CLOUD AND GREEN COMPUTING (CGC 2013), 2013, : 487 - 493
  • [24] An access control and authorization model with Open stack cloud for Smart Grid
    Rathod, Yagnik A.
    Kotwal, Chetan B.
    Pandya, Sohil D.
    Sondagar, Divyesh R.
    ADCAIJ-ADVANCES IN DISTRIBUTED COMPUTING AND ARTIFICIAL INTELLIGENCE JOURNAL, 2020, 9 (03): : 69 - 87
  • [25] The CQL continuous query language: semantic foundations and query execution
    Arasu, A
    Babu, S
    Widom, J
    VLDB JOURNAL, 2006, 15 (02): : 121 - 142
  • [26] Using snapshot query fidelity to adapt continuous query execution
    Payton, Jamie
    Julien, Christine
    Rajamani, Vasanth
    Roman, Gruia-Catalin
    PERVASIVE AND MOBILE COMPUTING, 2012, 8 (03) : 317 - 330
  • [27] Self-monitoring query execution for adaptive query processing
    Gounaris, A
    Paton, NW
    Fernandes, AAA
    Sakellariou, R
    DATA & KNOWLEDGE ENGINEERING, 2004, 51 (03) : 325 - 348
  • [28] The CQL continuous query language: semantic foundations and query execution
    Arvind Arasu
    Shivnath Babu
    Jennifer Widom
    The VLDB Journal, 2006, 15 : 121 - 142
  • [29] Filter Representation in Vectorized Query Execution
    Ngom, Amadou
    Menon, Prashanth
    Butrovich, Matthew
    Ma, Lin
    Lim, Wan Shen
    Mowry, Todd C.
    Pavlo, Andrew
    17TH INTERNATIONAL WORKSHOP ON DATA MANAGEMENT ON NEW HARDWARE, DAMON 2021, 2021,
  • [30] A cost model for the estimation of query execution time in a parallel environment supporting pipeline
    Spiliopoulou, M
    Hatzopoulos, M
    Vassilakis, C
    COMPUTERS AND ARTIFICIAL INTELLIGENCE, 1996, 15 (04): : 341 - 368