iDataGuard: an interoperable security middleware for untrusted internet data storage

R. Jammalamadaka, Roberto Gamboni, S. Mehrotra, K. Seamons, N. Venkatasubramanian
{"title":"iDataGuard: an interoperable security middleware for untrusted internet data storage","authors":"R. Jammalamadaka, Roberto Gamboni, S. Mehrotra, K. Seamons, N. Venkatasubramanian","doi":"10.1145/1462735.1462744","DOIUrl":null,"url":null,"abstract":"Businesses that provide data storage facilities on the internet (IDP) have exploded recently. Such businesses provide the following benefits to end users: a) anytime, anywhere access to data; b) low cost; and c) good quality of service. Examples of data storage providers include Amazon S3 service, Windows SkyDrive, Nirvarnix, etc.\n Users face two challenges in utilizing the storage infrastructures of the IDPs: a) Heterogeneity: Different IDPs provide different interfaces to application developers to store and fetch data with them due to lack of accepted standards; and b) Security: Data outsourced to IDPs is vulnerable to attacks from internet thieves and from malicious employees of IDPs.\n In this paper, we present the design of iDataGuard, a client side interoperable security middleware that adapts to the heterogeneity of interfaces of IDPs and enforces security constraints on outsourced data. This significantly simplifies the effort for application development. To combat heterogeneity, iDataGuard incorporates an abstract service model that can be easily customized to individual IDPs. To address the security challenges, iDataGuard supports a security model that protects the confidentiality and integrity of outsourced data. We propose a novel indexing technique that allows search on the encrypted data stored at the IDPs. We illustrate the feasibility/efficacy of iDataGuard by implementing the middleware and executing it on two popular IDPs, Amazon S3 service and Gmail.com.","PeriodicalId":340887,"journal":{"name":"Companion '08","volume":"27 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2008-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"16","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Companion '08","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/1462735.1462744","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 16

Abstract

Businesses that provide data storage facilities on the internet (IDP) have exploded recently. Such businesses provide the following benefits to end users: a) anytime, anywhere access to data; b) low cost; and c) good quality of service. Examples of data storage providers include Amazon S3 service, Windows SkyDrive, Nirvarnix, etc. Users face two challenges in utilizing the storage infrastructures of the IDPs: a) Heterogeneity: Different IDPs provide different interfaces to application developers to store and fetch data with them due to lack of accepted standards; and b) Security: Data outsourced to IDPs is vulnerable to attacks from internet thieves and from malicious employees of IDPs. In this paper, we present the design of iDataGuard, a client side interoperable security middleware that adapts to the heterogeneity of interfaces of IDPs and enforces security constraints on outsourced data. This significantly simplifies the effort for application development. To combat heterogeneity, iDataGuard incorporates an abstract service model that can be easily customized to individual IDPs. To address the security challenges, iDataGuard supports a security model that protects the confidentiality and integrity of outsourced data. We propose a novel indexing technique that allows search on the encrypted data stored at the IDPs. We illustrate the feasibility/efficacy of iDataGuard by implementing the middleware and executing it on two popular IDPs, Amazon S3 service and Gmail.com.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
iDataGuard:一个可互操作的安全中间件,用于不受信任的互联网数据存储
在互联网上提供数据存储设施(IDP)的企业最近出现了爆炸式增长。这些业务为最终用户提供了以下好处:a)随时随地访问数据;B)低成本;c)服务质量好。数据存储提供商的例子包括Amazon S3服务、Windows SkyDrive、Nirvarnix等。用户在利用idp的存储基础设施时面临两个挑战:a)异构性:由于缺乏公认的标准,不同的idp为应用程序开发人员提供不同的接口来存储和获取数据;b)安全性:外包给国内流离失所者的数据容易受到网络窃贼和国内流离失所者恶意雇员的攻击。在本文中,我们提出了iDataGuard的设计,这是一个客户端可互操作的安全中间件,它适应idp接口的异构性,并对外包数据实施安全约束。这极大地简化了应用程序开发的工作。为了对抗异构性,iDataGuard集成了一个抽象的服务模型,可以很容易地针对个人idp进行定制。为了应对这些安全挑战,iDataGuard支持一种安全模型,可以保护外包数据的机密性和完整性。我们提出了一种新的索引技术,允许搜索存储在国内数据中心的加密数据。我们通过实现中间件并在两个流行的idp (Amazon S3服务和Gmail.com)上执行它来说明iDataGuard的可行性/有效性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Implementing remote monitoring to the PeerHood middleware Using the service coroner tool for diagnosing stale references in the OSGi platform Event-based data control in healthcare FOREVER: Fault/intrusiOn REmoVal through Evolution & Recovery A flexible architecture for mobile collaboration services
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1