10 Secure Outsourcing of Geographical Data
229
the same (encrypted) query he/she has submitted to publishers. Completeness verification can be done for all XPath queries whose conditions are based on =, <, <=,
>, >= operators or the contains() function. Users verify the completeness of query
results by comparing the node-set returned by the publisher with the node-set resulting from the query evaluation on the query template. More details on completeness
verification can be found in [5].
10.5 Secure Outsourcing of Geographical Data
In this section, we show how the framework previously illustrated can be used for
secure geodata outsourcing. In particular, we consider a data owner, called hereafter
GisOwner, which is the producer of geographical data. GisOwner elaborates geographical data from satellites, cartographic maps, and so on and produces maps of
several geographical objects, defined according to different geodata models, that is,
with different features, level of details, and so on. All these maps are encoded in
GML (geography markup language) [24]. We assume that GisOwner makes its geographical data available to customers (i.e. users) on the basis of different subscription
fees. Furthermore, we suppose that it does not manage user interactions on its own,
rather it outsources the maps it produces to one or more publishers, which are in
charge of answering customers’ queries.
In order to keep the example simple, we limit the discussion to a unique GML
document, called CambridgeCityModel, defined according to a model for city-related
geographical data and encoding information about Cambridge’s rivers and roads (see
Fig. 10.4). Moreover, we assume that GisOwner offers three kinds of subscription:
River subscription, which allows customers to view only information on rivers, Road
subscription, authorizing customers to access road information, and Full subscription, which allows access to information on both rivers and roads. In what follows,
we show how, by exploiting the framework presented in Sect. 10.4.2, it is possible to
avoid publisher’s and user’s misuses of GisOwner’s data. Subscriptions can be modeled by means of access control policies. For instance, the River subscription can be
enforced by an access control policy acp 1 granting to all subscribed customers access to all and only river information (i.e. XML nodes containing river information).
Whereas, Roads and Full subscriptions can be modeled by similar access control
policies (referred to as acp 2 and acp 3 in what follows). Access control policies can
be specified by means of GEOXACML language [18], a geospatial extension to the
OASIS standard eXtensible access control markup language (XACML) [23].
According to the strategy introduced in Sect. 10.4.2, GisOwner selectively encrypts CambridgeCityModel and complements it with additional information, obtaining thus the corresponding SE-ENC document, which is then outsourced to publishers. In particular, since three different access control policies (i.e. subscriptions)
are applied to the CambridgeCityModel document, different portions of the document are encrypted with different keys. More precisely, in the resulting encrypted
Précédent

- 222/317

Suivant