10
Secure Outsourcing of Geographical Data
Over the Web: Techniques and Architectures
Barbara Carminati and Elena Ferrari
University of Insubria, Varese (Italy)
10.1 Introduction
Service outsourcing is today a widely-used paradigm by many companies and organizations. In the same vein, in recent years a new trend has emerged, that is, data
outsourcing [16]. Data outsourcing means moving from a traditional client–server
architecture (see Fig. 10.1(a)), where the data owner directly manages the DBMS
and answers user queries, to a third-party architecture (see Fig. 10.1(b)), where data
owners are no longer totally responsible for data management. Rather they outsource
their data (or portions of them) to one or more publishers that provide data management services and query processing functionalities. This paradigm has potentially
many benefits. The first is the cost reduction for the owner, in that it pays only for
services it uses from publishers and not for the deployment, installation, maintenance, and upgrades of costly DBMSs. Another important benefit is scalability in
that the data owner could not become a bottleneck for the system since it can outsource its data to as many publishers as it needs according to the amount of data and
the number of managed users.
Data outsourcing has many interesting applications in the geographical data domain. For instance, think about a geomarketing service. A data owner can outsource
some of its geographical data (e.g. maps at various levels of detail) to a publisher
that provides them to customers on the basis of different registration fees or different confidentiality requirements (e.g. maps of some regions cannot be distributed to
everyone because they might show sensitive objectives).
However, all the benefits of data outsourcing in terms of cost reduction and better
services are not enough to make data outsourcing widely adopted. One of the most
serious obstacle to the widespread use of data outsourcing is related to security. If security is not considered as a primary requirement, data outsourcing can be perceived
by the owner as “loss of control” over its data. The challenge is therefore how to ensure the most important security properties (i.e. confidentiality, integrity, authenticity) even if data are managed by a third-party. A naive solution is to assume the publisher is to be trusted, that is, to assume it always operates according to the owner’s
security policies. However, making this assumption is not realistic, especially for
Secure Outsourcing of Geographical Data
Over the Web: Techniques and Architectures
Barbara Carminati and Elena Ferrari
University of Insubria, Varese (Italy)
10.1 Introduction
Service outsourcing is today a widely-used paradigm by many companies and organizations. In the same vein, in recent years a new trend has emerged, that is, data
outsourcing [16]. Data outsourcing means moving from a traditional client–server
architecture (see Fig. 10.1(a)), where the data owner directly manages the DBMS
and answers user queries, to a third-party architecture (see Fig. 10.1(b)), where data
owners are no longer totally responsible for data management. Rather they outsource
their data (or portions of them) to one or more publishers that provide data management services and query processing functionalities. This paradigm has potentially
many benefits. The first is the cost reduction for the owner, in that it pays only for
services it uses from publishers and not for the deployment, installation, maintenance, and upgrades of costly DBMSs. Another important benefit is scalability in
that the data owner could not become a bottleneck for the system since it can outsource its data to as many publishers as it needs according to the amount of data and
the number of managed users.
Data outsourcing has many interesting applications in the geographical data domain. For instance, think about a geomarketing service. A data owner can outsource
some of its geographical data (e.g. maps at various levels of detail) to a publisher
that provides them to customers on the basis of different registration fees or different confidentiality requirements (e.g. maps of some regions cannot be distributed to
everyone because they might show sensitive objectives).
However, all the benefits of data outsourcing in terms of cost reduction and better
services are not enough to make data outsourcing widely adopted. One of the most
serious obstacle to the widespread use of data outsourcing is related to security. If security is not considered as a primary requirement, data outsourcing can be perceived
by the owner as “loss of control” over its data. The challenge is therefore how to ensure the most important security properties (i.e. confidentiality, integrity, authenticity) even if data are managed by a third-party. A naive solution is to assume the publisher is to be trusted, that is, to assume it always operates according to the owner’s
security policies. However, making this assumption is not realistic, especially for
