216
Barbara Carminati and Elena Ferrari
Fig. 10.1. (a) Two-party architecture; (b) third-party architecture
Web-based systems that can easily be attacked and penetrated. Additionally, verifying that a publisher is trusted is a very costly operation. Therefore, research is now
focusing on the definition of techniques to satisfy main security properties even in
the presence of an untrusted publisher that can maliciously modify/delete the data
it manages, for instance by inserting fake records, or it can send data to unauthorized users. Several proposals can be found in the literature [13–17, 19, 22, 26],
each of which focuses on a single security property and on data organized according to a specific data model (e.g. relational, XML). Such techniques, which
we survey in Sect. 10.3.1, make use of encryption, to enforce confidentiality requirements and of non-standard digital signature techniques to enforce authenticity/integrity. What is still missing in these proposals is a comprehensive framework
able to enforce all the above-mentioned security properties in a unified manner. For
this reason, in the second part of the chapter we present our proposal for a framework providing a comprehensive solution to the problem of secure outsourcing of
XML data, and we show how this framework can be successfully used in the GIS
domain.
The remainder of this chapter is organized as follows. Section 10.2 discusses
the requirements for secure outsourcing. Section 10.3 surveys the most important techniques that have been proposed so far for secure data outsourcing. Section 10.4 presents a comprehensive framework for the secure outsourcing of XML
data, whereas Sect. 10.5 shows how this framework can be applied to geographical data. Finally, Sect. 10.6 concludes the chapter and outlines future research
directions.
10.2 Security Requirements
Information security is one of the main assets of each organization, from the smallest
company to international corporations. To have an idea of its key role in
decision-making processes, let us consider the e-business world. Today, a company
that wants to move to e-commerce has, as primary requirement, to provide a secure system. Indeed, no matter whether you are the best in your business or how
cheap your prices are, today e-commerce customers do not take into account only
Barbara Carminati and Elena Ferrari
Fig. 10.1. (a) Two-party architecture; (b) third-party architecture
Web-based systems that can easily be attacked and penetrated. Additionally, verifying that a publisher is trusted is a very costly operation. Therefore, research is now
focusing on the definition of techniques to satisfy main security properties even in
the presence of an untrusted publisher that can maliciously modify/delete the data
it manages, for instance by inserting fake records, or it can send data to unauthorized users. Several proposals can be found in the literature [13–17, 19, 22, 26],
each of which focuses on a single security property and on data organized according to a specific data model (e.g. relational, XML). Such techniques, which
we survey in Sect. 10.3.1, make use of encryption, to enforce confidentiality requirements and of non-standard digital signature techniques to enforce authenticity/integrity. What is still missing in these proposals is a comprehensive framework
able to enforce all the above-mentioned security properties in a unified manner. For
this reason, in the second part of the chapter we present our proposal for a framework providing a comprehensive solution to the problem of secure outsourcing of
XML data, and we show how this framework can be successfully used in the GIS
domain.
The remainder of this chapter is organized as follows. Section 10.2 discusses
the requirements for secure outsourcing. Section 10.3 surveys the most important techniques that have been proposed so far for secure data outsourcing. Section 10.4 presents a comprehensive framework for the secure outsourcing of XML
data, whereas Sect. 10.5 shows how this framework can be applied to geographical data. Finally, Sect. 10.6 concludes the chapter and outlines future research
directions.
10.2 Security Requirements
Information security is one of the main assets of each organization, from the smallest
company to international corporations. To have an idea of its key role in
decision-making processes, let us consider the e-business world. Today, a company
that wants to move to e-commerce has, as primary requirement, to provide a secure system. Indeed, no matter whether you are the best in your business or how
cheap your prices are, today e-commerce customers do not take into account only
