10 Secure Outsourcing of Geographical Data
225
the result set. Thus, the user is ensured that the query answer is complete, that is, no
tuples are missing from the result set.
By contrast, the approach presented in [22] modifies an aggregation signature
scheme to include in the signature of a tuple t the hash value of tuples preceding t
according to all possible sortings defined on the relation’s attributes. Then, the thirdparty inserts into the range query’s answer the boundary tuples, that is, the tuples
preceding the upper and lower bound of the result set, as well as their aggregated
signatures. By means of the signature chain, a user is able to prove that the thirdparty has not omitted any tuple.
10.4 A Comprehensive Approach to Secure Data Outsourcing
In this section we present our proposal for secure outsourcing of data, whereas in
Sect. 10.5 we show how it can be applied to the outsourcing of geographical data.
The framework has been developed for the protection of XML data. A key feature
of our proposal is that it does not rely on trusted publishers. The framework we
present assures authenticity, confidentiality, and completeness requirements of both
information owners and requesting users. This is obtained through the use of nonconventional signature and encryption strategies.
The framework (see Fig. 10.3) is a classical third-party architecture. Users submit queries
7 to publishers through a client, which the user can download from the
owner site.
Security properties enforcement requires additional information to be transmitted by the owner to both publishers and users. All such information is coded in XML
and is stored in a directory server managed by owners. Keys for accessing directory entries are received by users/publishers after a mandatory registration phase.
In particular, all additional information needed by publishers for confidentiality and
authenticity/integrity enforcement is attached to the document sent to publishers,
forming the so-called Security Enhanced ENCryption (SE-ENC) of the original document. All SE-ENC documents are stored by the owner in the publishers’ directory
entry. Similarly, all information needed by a user to verify security properties is encoded by publishers in XML and attached to the query answer, resulting in what we
call the reply document.
In the following, we illustrate how each security property is enforced (the techniques employed are summarized in Table 10.2). More details can be found in
[5, 7, 9].
10.4.1 Authenticity and Integrity
Authenticity and integrity are enforced by applying Merkle hash trees to XML documents. According to this approach, we univocally associate a hash value to the
document root (i.e the digest, referred to as Merkle hash value) through a recursive
bottom-up computation on its structure. The digest is computed by associating a
Merkle hash value with each node n of the XML document. The Merkle hash value
7 Queries are formulated in XPath [28].
225
the result set. Thus, the user is ensured that the query answer is complete, that is, no
tuples are missing from the result set.
By contrast, the approach presented in [22] modifies an aggregation signature
scheme to include in the signature of a tuple t the hash value of tuples preceding t
according to all possible sortings defined on the relation’s attributes. Then, the thirdparty inserts into the range query’s answer the boundary tuples, that is, the tuples
preceding the upper and lower bound of the result set, as well as their aggregated
signatures. By means of the signature chain, a user is able to prove that the thirdparty has not omitted any tuple.
10.4 A Comprehensive Approach to Secure Data Outsourcing
In this section we present our proposal for secure outsourcing of data, whereas in
Sect. 10.5 we show how it can be applied to the outsourcing of geographical data.
The framework has been developed for the protection of XML data. A key feature
of our proposal is that it does not rely on trusted publishers. The framework we
present assures authenticity, confidentiality, and completeness requirements of both
information owners and requesting users. This is obtained through the use of nonconventional signature and encryption strategies.
The framework (see Fig. 10.3) is a classical third-party architecture. Users submit queries
7 to publishers through a client, which the user can download from the
owner site.
Security properties enforcement requires additional information to be transmitted by the owner to both publishers and users. All such information is coded in XML
and is stored in a directory server managed by owners. Keys for accessing directory entries are received by users/publishers after a mandatory registration phase.
In particular, all additional information needed by publishers for confidentiality and
authenticity/integrity enforcement is attached to the document sent to publishers,
forming the so-called Security Enhanced ENCryption (SE-ENC) of the original document. All SE-ENC documents are stored by the owner in the publishers’ directory
entry. Similarly, all information needed by a user to verify security properties is encoded by publishers in XML and attached to the query answer, resulting in what we
call the reply document.
In the following, we illustrate how each security property is enforced (the techniques employed are summarized in Table 10.2). More details can be found in
[5, 7, 9].
10.4.1 Authenticity and Integrity
Authenticity and integrity are enforced by applying Merkle hash trees to XML documents. According to this approach, we univocally associate a hash value to the
document root (i.e the digest, referred to as Merkle hash value) through a recursive
bottom-up computation on its structure. The digest is computed by associating a
Merkle hash value with each node n of the XML document. The Merkle hash value
7 Queries are formulated in XPath [28].
