首页> 外文会议>Applied Cryptography and Network Security >Restricted Queries over an Encrypted Index with Applications to Regulatory Compliance
【24h】

Restricted Queries over an Encrypted Index with Applications to Regulatory Compliance

机译:加密索引的受限查询以及适用于法规遵从的应用

获取原文
获取原文并翻译 | 示例

摘要

Compliance storage is an increasingly important area for businesses faced with a myriad of new document retention regulations. Today, businesses have turned to Write-One Read Many (WORM) storage technology to achieve compliance. But WORM answers only a part of the compliance puzzle; in addition to guaranteed document retention, businesses also need secure indexing, to ensure auditors can find required documents in a large database, secure deletion to expire documents (and their index entries) from storage once they are past their expiry period, and support for litigation holds, which require that certain documents are retained pending the resolution of active litigation. We build upon previous work in compliance storage and attribute-based encryption to design a system that satisfies all three of these requirements. In particular, we design a new encrypted index, which allows the owner of a database of documents to grant access to only those documents that match a particular query. This enables litigation holds for expired documents, and at the same time restricts auditor access for un-expired documents, greatly limiting the potential for auditor abuse as compared to previous work. We show by way of formal security proofs that our construction is secure and that it prevents reconstruction attacks wherein the index is used to recover the contents of the document. Our experiments show that our scheme can be practical for large databases and moderate sizes of queries.
机译:对于面对无数新文档保留法规的企业而言,法规遵从性存储已变得越来越重要。如今,企业已转向“一次写入多次读取”(WORM)存储技术来实现合规性。但是,WORM只能解决合规难题的一部分。除了保证文档保留之外,企业还需要安全的索引编制,以确保审核员可以在大型数据库中找到所需的文档,安全删除以在过期后将过期的文档(及其索引条目)从存储中删除,并支持诉讼保留,要求保留某些文件,以待进行中的诉讼解决。我们以以前在合规性存储和基于属性的加密方面的工作为基础,设计出可以满足所有这三个要求的系统。特别是,我们设计了一个新的加密索引,该索引允许文档数据库的所有者仅授予对与特定查询匹配的那些文档的访问权限。这样就可以对过期文件进行诉讼保留,同时限制了审核员对未过期文件的访问权限,与以前的工作相比,极大地限制了审核员滥用的可能性。我们通过形式上的安全证明来证明我们的结构是安全的,并且可以防止重建攻击,其中索引用于恢复文档的内容。我们的实验表明,我们的方案对于大型数据库和中等大小的查询是可行的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号