10 Secure Outsourcing of Geographical Data
231
< E k 123 (CityModel)>
< E k 13 (River)>
...
< E k 13 (gml:LineString)>
< E k 13 (gml:coord)>
< E k 13 (gml:X)>


< Query-Info > PF(0)


< /E k 13 (gml:X)>
< E k 13 (gml:Y)>
....
< /E k 13 (gml:Y)>
< E k 13 (gml:coord)>
< E k 13 (gml:X)>


< Query-Info > PF(70)


< /E k 13 (gml:X)>
< E k 13 (gml:Y)>
....
< /E k 13 (gml:Y)>
< /E k 13 (gml:coord)>
< E k 13 (gml:coord)>
< E k 13 (gml:X)>


< Query-Info > PF(100)


< /E k 13 (gml:X)>
< E k 13 (gml:Y)>
...
< /E k 13 (gml:Y)>
< /E k 13 (gml:coord)>
< /E k 13 (gml:LineString)>
< /E k 13 (River)>
< /E k 123 (CityModel)>
Fig. 10.5. An example of Sec-Info element
document, River elements and Road elements are encrypted with two different keys,
say k 13 and k 23
8 respectively.
Figure 10.5 presents a simplified version of the resulting SE-ENC document,
where all additional information needed to make the publisher able to evaluate
queries on the encrypted document is inserted into the Sec-Info element. We recall that this information is the partition ids defined over the data domain of elements/attributes.
Let us suppose now that a customer having the River subscription wants to
retrieve information about all rivers in Cambridge having X coordinate equal to
100 (see Fig. 10.4). By having information on partition functions, the customer is
8 We adopt a notation where the key’s subscripts are stated according to the ids of the access
control policies associated with that key. Thus, for instance, k 23 denotes the key that should
be delivered to users satisfying acp 2 and acp 3 .
Précédent

- 224/317

Suivant