10 Secure Outsourcing of Geographical Data
217
the quality of services, rather they want to be assured also about a company’s behavior with respect to security requirements. Let us now consider the outsourcing
scenario. Here, we have companies/organizations/enterprises delegating their data to
external entities. They basically provide another organization the core of their business, that is their data. The basic questions about security are as follows: How can
a company be assured that its data are not maliciously modified by the third entity
before being distributed to requesting subjects? How can a company be assured that
the third entity does not provide company data to unauthorized users, including, for
instance, competitors? From the user-side point of view the main security-related
questions are as follows: How can a user be sure that the third-party does not maliciously modify/delete data it is authorized to access? How can the user be sure
he/she has received all data it is authorized to access? Thus, it is obvious that in
order to make the outsourcing paradigm well accepted and widespread, it is necessary to fulfill the main security requirements of both data owners and end users. A
first step toward this is to point out the main security requirements that need to be
addressed for secure outsourcing. In what follows we introduce and motivate some
of them.
Confidentiality. In general, ensuring data confidentiality means that the data (or
portions of it) can be disclosed only to users authorized according to access control
policies stated by data owners (see Chap. 9 for issues related to access control for
geographical data). However, it is obvious that when data are outsourced, confidentiality requirements are not limited to users. Indeed, in outsource-based architectures
it is possible to point out two main confidentiality issues. The first, hereafter called
confidentiality with respect to users, refers to protect data against unauthorized read
operations by users. In general, confidentiality requirements with respect to users
are modeled through a set of access control policies stating who can access what
portions of the owner’s data. In traditional client–server architectures, confidentiality with respect to users is usually enforced by means of access control mechanisms
(i.e. reference monitors), which mediate each user access request by authorizing only
those in accordance with the owner’s access control policies. The key component is
therefore the reference monitor, that is the software module in charge of enforcing
access control policies. A fundamental requirement is therefore the presence of a
trusted environment hosting the reference monitor. In traditional scenarios, this environment is provided by the entity managing the data, that is the owner’s DBMS
server. Enforcing access control in a third-party scenario would imply the delegation
of the reference monitor tasks to publishers. However, since we are considering a
scenario where assumptions on publisher trustworthiness cannot be made, such a solution is no longer applicable and alternative solutions should be devised (we survey
some of them in Sect. 10.3.1).
Furthermore, in a scenario where data are outsourced to external publishers, confidentiality issues are also related to publishers. There thus exists a second relevant
confidentiality requirement, called confidentiality with respect to publishers, which
deals with protecting owner’s data from read operations by publishers. Indeed, since
Précédent

- 210/317

Suivant