计算机应用 ›› 2010, Vol. 30 ›› Issue (10): 2672-2676.

• 信息安全 • 上一篇    下一篇

外包数据库服务隐私保护方法

余永红1,柏文阳2   

  1. 1. 安徽财经大学
    2.
  • 收稿日期:2010-04-20 修回日期:2010-06-09 发布日期:2010-09-21 出版日期:2010-10-01
  • 通讯作者: 余永红
  • 基金资助:
    国家863计划项目;安徽高校省级自然科学研究重点项目;南京大学计算机软件新技术国家重点实验室开放课题

Privacy protection method for outsourced database services

  • Received:2010-04-20 Revised:2010-06-09 Online:2010-09-21 Published:2010-10-01

摘要: 针对目前基于数据库加密的隐私保护外包数据库服务技术需要对整个数据库进行频繁的加密和解密操作,不能有效实现数据处理性能与数据隐私保护之间平衡的不足,提出一种新的基于分布式外包数据库服务的隐私保护方法。该方法引入准标识属性集自动检测和概率匿名隐私保护技术,采用对部分敏感属性加密或匿名的方式和分解准标识属性集的方式实现数据的水平分解和垂直分解,并针对不同的数据分解方式,给出了分布式查询处理的方案。理论分析和实验结果表明,该方法可实现非可信数据库服务器的外包,并能较好地平衡数据查询性能和隐私保护之间的矛盾。

关键词: 外包数据库服务, 隐私保护, 准标识集, 关系分解, 分布式查询

Abstract: In privacy protection based on database encryption technology for outsourcing database services, it is difficult to achieve balance between performance of data processing and privacy protection effectively. A new privacy protection method based on distributed outsourcing database service was proposed to provide both efficient privacy protection and query processing. Automatic quasi-identifiers detection and probabilistic anonymity were introduced. The data could be partitioned across many logically independent database servers horizontally or vertically, while only few sensitive data were encrypted or anonymous. According to the type of data fragmentation, the trusted client executed queries by transmitting appropriate sub-queries to different databases, and then pieced the results together at the client side. The theoretical analysis and experimental results show that the proposed method is well-balanced in dealing with the contradiction between data privacy preserving and efficient query processing.

Key words: outsourced database service, privacy protection, quasi-identifier, relation fragmentation, distributed query

中图分类号: