226
Barbara Carminati and Elena Ferrari
User
Answer
Query
Subscription
Request
Publisher
entry key
outsourced
documents
User_ID
Users
entry Key
Subscription
Request
Directory server
Query Template
documents
encryption
keys
Answer
Query
OWNER
OWNER
CLIENT
CLIENT
PUBLISHER
PUBLISHER
Publishers
Users
User_ID
User_ID
Users
entry Key
Publisher
entry key
Fig. 10.3. Overall architecture
Table 10.2. Secure outsourcing: adopted techniques
security properties
techniques
authenticity/integrity
Merkle signatures, Merkle hash paths
Confidentiality:
with respect to users
access control policies, selective encryption
with respect to publishers
encryption, encrypted queries
completeness
query templates
of a node depends on one of its children and attributes. The digest of the whole document is the Merkle hash value of the root of the document. The Merkle Signature
is the encryption of the digest with owner’s private key. The Merkle signature is inserted by the owner into the corresponding SE-ENC document by adding a Sign
subelement to the document root. When a user submits a query, the publisher returns
him/her, besides the query result, also the Merkle signatures of the documents on
which the query is performed. However, this is not enough to enable a user to validate owner’s signatures. What he/she needs are the Merkle hash values of the missing
nodes, that is, those nodes of the original document which are not contained in the
query answer. This is formalized by the notion of Merkle hash paths, that is, the
minimum set of hash values needed by the requesting user to validate the received
signature, starting from the received answer [5].
Since publishers do not operate on clear-text data (see Section 9.4.2 for more details), they cannot compute Merkle hash values. Therefore, the owner complements
Barbara Carminati and Elena Ferrari
User
Answer
Query
Subscription
Request
Publisher
entry key
outsourced
documents
User_ID
Users
entry Key
Subscription
Request
Directory server
Query Template
documents
encryption
keys
Answer
Query
OWNER
OWNER
CLIENT
CLIENT
PUBLISHER
PUBLISHER
Publishers
Users
User_ID
User_ID
Users
entry Key
Publisher
entry key
Fig. 10.3. Overall architecture
Table 10.2. Secure outsourcing: adopted techniques
security properties
techniques
authenticity/integrity
Merkle signatures, Merkle hash paths
Confidentiality:
with respect to users
access control policies, selective encryption
with respect to publishers
encryption, encrypted queries
completeness
query templates
of a node depends on one of its children and attributes. The digest of the whole document is the Merkle hash value of the root of the document. The Merkle Signature
is the encryption of the digest with owner’s private key. The Merkle signature is inserted by the owner into the corresponding SE-ENC document by adding a Sign
subelement to the document root. When a user submits a query, the publisher returns
him/her, besides the query result, also the Merkle signatures of the documents on
which the query is performed. However, this is not enough to enable a user to validate owner’s signatures. What he/she needs are the Merkle hash values of the missing
nodes, that is, those nodes of the original document which are not contained in the
query answer. This is formalized by the notion of Merkle hash paths, that is, the
minimum set of hash values needed by the requesting user to validate the received
signature, starting from the received answer [5].
Since publishers do not operate on clear-text data (see Section 9.4.2 for more details), they cannot compute Merkle hash values. Therefore, the owner complements
