10 Secure Outsourcing of Geographical Data
227
SE-ENC documents with the Merkle hash value of each node. By having these hash
values, the publisher is able to locally generate Merkle hash paths, without the need
for accessing clear-text data.
10.4.2 Confidentiality
Confidentiality with respect to publishers is obtained through the use of symmetric encryption. The idea is quite straightforward: owners encrypt data before sending them to publishers. Publishers do not receive any decryption key and therefore
owner’s confidentiality requirements are enforced.
By contrast, enforcing confidentiality with respect to final users first requires the
specification of a set of access control policies, stating which user can access which
portions of owner’s data. In our framework, these policies are specified through a
credential-based access control model for XML documents proposed in [4]. To enforce confidentiality with respect to users, data managed by publishers are not encrypted with a single key, rather they are encrypted with different keys on the basis
of owner’s access control policies. All data portions to which the same policies apply
(and therefore accessible by the same users) are encrypted with the same key. Then,
each user receives from owners (in the corresponding entry of the directory server)
all and only the keys corresponding to data portions he/she can access according to
the specified policies.
The main weak point of this solution is that it may require the management
of a great number of keys. To limit the number of keys that need to be generated, our system adopts a hierarchical key assignment scheme which requires one
to permanently store, in the worst case, a number of keys linear in the number
of specified access control policies. A hierarchical key assignment scheme [2] relies on the existence of a hierarchical organization (e.g. over data, security levels, roles, etc.) and it is defined in such a way that from the key associated with
a level j in the hierarchy, it is possible to derive all and only the keys associated
with a lower level i, where i j, and is the partial order defined by the hierarchy. To limit the number of keys, we exploit the partial order that can be defined over possible access control policies configurations. Therefore, by the properties of hierarchical key management schemes, from the encryption key associated
with an access control policy acp j , we are able to derive all and only the encryption
keys associated with access control policy configurations containing acp j . These
keys can be derived on the fly when needed and do not need to be permanently
stored and maintained. We refer the interested reader to [3] for all the details on key
generation.
Clearly, enforcing confidentiality through encryption requires enabling publishers to answer queries over encrypted data. For this purpose, we adopt an approach similar to the one proposed in [15] for relational databases (cf. Sect. 10.3.1),
and we extend it to deal with XML data and data encryptions generated with
multiple keys. The basic idea is to divide the domain of each document node
(i.e. attribute and element) into distinguished partitions, to which a unique id is assigned. Then, the owner provides publishers the ids of the partitions corresponding
227
SE-ENC documents with the Merkle hash value of each node. By having these hash
values, the publisher is able to locally generate Merkle hash paths, without the need
for accessing clear-text data.
10.4.2 Confidentiality
Confidentiality with respect to publishers is obtained through the use of symmetric encryption. The idea is quite straightforward: owners encrypt data before sending them to publishers. Publishers do not receive any decryption key and therefore
owner’s confidentiality requirements are enforced.
By contrast, enforcing confidentiality with respect to final users first requires the
specification of a set of access control policies, stating which user can access which
portions of owner’s data. In our framework, these policies are specified through a
credential-based access control model for XML documents proposed in [4]. To enforce confidentiality with respect to users, data managed by publishers are not encrypted with a single key, rather they are encrypted with different keys on the basis
of owner’s access control policies. All data portions to which the same policies apply
(and therefore accessible by the same users) are encrypted with the same key. Then,
each user receives from owners (in the corresponding entry of the directory server)
all and only the keys corresponding to data portions he/she can access according to
the specified policies.
The main weak point of this solution is that it may require the management
of a great number of keys. To limit the number of keys that need to be generated, our system adopts a hierarchical key assignment scheme which requires one
to permanently store, in the worst case, a number of keys linear in the number
of specified access control policies. A hierarchical key assignment scheme [2] relies on the existence of a hierarchical organization (e.g. over data, security levels, roles, etc.) and it is defined in such a way that from the key associated with
a level j in the hierarchy, it is possible to derive all and only the keys associated
with a lower level i, where i j, and is the partial order defined by the hierarchy. To limit the number of keys, we exploit the partial order that can be defined over possible access control policies configurations. Therefore, by the properties of hierarchical key management schemes, from the encryption key associated
with an access control policy acp j , we are able to derive all and only the encryption
keys associated with access control policy configurations containing acp j . These
keys can be derived on the fly when needed and do not need to be permanently
stored and maintained. We refer the interested reader to [3] for all the details on key
generation.
Clearly, enforcing confidentiality through encryption requires enabling publishers to answer queries over encrypted data. For this purpose, we adopt an approach similar to the one proposed in [15] for relational databases (cf. Sect. 10.3.1),
and we extend it to deal with XML data and data encryptions generated with
multiple keys. The basic idea is to divide the domain of each document node
(i.e. attribute and element) into distinguished partitions, to which a unique id is assigned. Then, the owner provides publishers the ids of the partitions corresponding
