开放大数据安全存储与检索系统
网络出版日期: 2024-11-16
基金资助
国家重点研发计划(2021YFB3101100);国家自然科学基金(62232013,62202364);博士后创新人才支持计划(BX20230279);陕西省重点研发计划(2024GX-YBXM-075,2023-ZDLGY-52)
版权
Secure Storage and Retrieval System for Open Big Data
Online published: 2024-11-16
Copyright
数据安全存储与检索是开放大数据安全利用的基础。然而,现有大数据存储与检索系统难以支持存储密钥的高效更新,且无法兼顾多模态数据的密文存储与高效检索,难以满足开放大数据的安全高效利用需求。为此,针对存储密钥更新问题,提出了基于嵌套加密的存储密钥更新机制,支持非解密式存储密钥高效更新,满足非可信环境下密钥定期轮换需求;针对密文索引体积膨胀问题,提出了压缩密文多集合查询过滤器,支持海量数据的高密度密文索引;针对多模态数据密文检索问题,提出了跨类型密文复合关联检索算法,支持文本、空间、图像等多模态数据的单类型和跨类型密文检索。基于以上关键技术研发了多模态加密数据库系统,该系统支持存储计算分离,兼容现有大数据服务的技术架构,现有大数据平台可通过微服务增量部署完成安全加固,保障系统的可扩展性、易用性和高效性。实验结果表明,相比传统的解密重加密机制,所提出的存储密钥更新机制性能提高了80%以上;相比现有的明文数据库系统,所提出的多模态加密数据库系统在文本、空间、图像、跨模态检索等方面综合性能损耗不超过25%。
王祥宇 , 马鑫迪 , 梁岩荣 , 何之洲 , 马建峰 . 开放大数据安全存储与检索系统[J]. 网络空间安全科学学报, 2024 , 2(3) : 13 -26 . DOI: 10.20172/j.issn.2097-3136.240302
The secure storage and retrieval of data are essential for the secure utilization of open big data. However, existing big data storage and retrieval systems struggle to update storage keys and cannot handle both secure storage and efficient retrieval of multi-modal data. To address the issue of storage key update, a storage key update mechanism based on nested encryption was proposed, which supports efficient non-decrypted key update to meet the requirement for regular key rotation in untrusted environments. To solve the problem of index volume expansion, a compressed encrypted multi-set query filter was proposed to support high-density ciphertext indexing of massive data. Aiming at multi-modal data retrieval on encrypted data, a cross-type ciphertext composite association retrieval algorithm was designed to support single-type and cross-type retrieval of multi-modal encrypted data such as text, spatial, and images. Based on the above technologies, a multi-modal encrypted database system was designed, which supported the separation of storage and computing and was compatible with the technical architecture of existing big data services. The existing big data platform can be upgraded through incremental deployment of microservices to ensure system scalability and efficiency. Experimental results show that the key update performance of the proposed storage key update mechanism improve by over 80% compared to the traditional re-encryption mechanism. Compared to the existing plaintext database system, the overall performance loss of the proposed multi-modal encrypted database system in terms of text, space, image, and cross-modal retrieval does not exceed 25%.
表 1 加密数据库技术路线特性对比Table 1 Comparison of technical routes for encrypted databases |
| 技术路线 | 功能性 | 性能 | 部署难度 | 稳定性 |
| 基于密文检索 的加密数据库 | 中 | 中 | 低 | 高 |
| 难以支持跨模态检索 | 索引膨胀较大,检索效率较高 | 支持单服务器部署,无需可信硬件 | 仅需单服务器 实时在线 | |
| 基于可信执行环 境的加密数据库 | 高 | 高 | 中 | 中 |
| 支持任意检索 | 无索引膨胀,检索效率高 | 支持单服务器部署,需要可信硬件 | 需要服务器和 可信执行环境实时通信 | |
| 基于分布式信任 的加密数据库 | 高 | 中 | 高 | 低 |
| 理论上支持任意检索 | 索引膨胀较小,检索效率较高 | 需要多个非共谋服务器,无需可信硬件 | 需要所有非共谋服务器 实时在线通信 |
| 1 |
BONEH D,LEWI K,MONTGOMERY H,et al. Key homomorphic PRFs and their applications[C]//Proceedings of the Annual Cryptology Conference,2013:410-428.
|
| 2 |
BOYD C,DAVIES G T,GJØSTEEN K,et al. Fast and secure updatable encryption[C]// Proceedings of the Annual International Cryptology Conference,2020:464-493.
|
| 3 |
LEHMANN A,TACKMANN B. Updatable encryption with post-compromise security[C]// Proceedings of the Advances in Cryptology-EUROCRYPT 2018:37th Annual International Conference on the Theory and Applications of Cryptographic Techniques,2018:685-716.
|
| 4 |
BONEH D,ESKANDARIAN S,KIM S,et al. Improving speed and security in updatable encryption schemes[C]//Proceedings of Advances in Cryptology-ASIACRYPT 2020:26th International Conference on the Theory and Application of Cryptology and Information Security,2020:559-589.
|
| 5 |
SONG D X,WAGNER D,PERRIG A. Practical techniques for searches on encrypted data[C]//Proceeding of the 2000 IEEE Symposium on Security and Privacy. S&P 2000. IEEE,2000:44-55.
|
| 6 |
BONEH D,CRESCENZO G D,OSTROVSKY R,et al. Public key encryption with keyword search[J]. Eurocrypt 2004,2004.
|
| 7 |
GOLLE P,STADDON J,WATERS B. Secure conjunctive keyword search over encrypted data[C]//Proceeding of the Applied Cryptography and Network Security:Second International Conference,ACNS 2004,2004.
|
| 8 |
LI F, MA J, MIAO Y, et. al. A survey on searchable symmetric encryption[J]. ACM Computing Surveys, 2023, 56 (5): 1- 42.
|
| 9 |
LIANG Y, MA J, MIAO Y, et al. Privacy-preserving bloom filter-based keyword search over large encrypted cloud data[J]. IEEE Transactions on Computers, 2023, 72 (11): 3086- 3098.
|
| 10 |
WANG X, MA J, MIAO Y, et al. Privacy-preserving diverse keyword search and online pre-diagnosis in cloud computing[J]. IEEE Transactions on Services Computing, 2022, 15 (2): 710- 723.
|
| 11 |
WONG W,CHEUNG D,KAO B,et al. Secure kNN computation on encrypted databases[C]//Proceedings of the ACM SIGMOD International Conference on Management of Data,SIGMOD 2009,2009.
|
| 12 |
XU G, LI H, DAI Y, et al. Enabling efficient and geometric range query with access control over encrypted spatial data[J]. IEEE Transactions on Information Forensics and Security, 2018, 14 (4): 870- 885.
|
| 13 |
WANG F, ZHU H, HE G, et al. Efficient and privacy-preserving arbitrary polygon range query scheme over dynamic and time-series location data[J]. IEEE Transactions on Information Forensics and Security, 2023, 18, 3414- 3429.
|
| 14 |
GONG Z, LI J, LIN Y, et al. Efficient privacy-preserving geographic keyword boolean range query over encrypted spatial data[J]. IEEE Systems Journal, 2023, 17 (1): 455- 466.
|
| 15 |
WANG X, MA J, LIU X, et al. Forward/backward and content private DSSE for spatial keyword queries[J]. IEEE Transactions on Dependable and Secure Computing, 2023, 20 (4): 3358- 3370.
|
| 16 |
MIAO Y, YANG Y, LI X, et al. Efficient privacy-preserving spatial range query over outsourced encrypted data[J]. IEEE Transactions on Information Forensics and Security, 2023, 18, 3921- 3933.
|
| 17 |
TONG Q, MIAO Y, CHEN L, et al. VFIRM: Verifiable fine-grained encrypted image retrieval in multi-owner multi-user settings[J]. IEEE Transactions on Services Computing, 2022, 15 (6): 3606- 3619.
|
| 18 |
XIA Z, WANG L, TANG J, et al. A privacy-preserving image retrieval scheme using secure local binary pattern in cloud computing[J]. IEEE Transactions on Network Science and Engineering, 2021, 8 (1): 318- 330.
|
| 19 |
LI Y, MA J, MIAO Y, et al. DVREI: Dynamic verifiable retrieval over encrypted images[J]. IEEE Transactions on Computers, 2022, 71 (8): 1755- 1769.
|
| 20 |
YANG T, MA J, MIAO Y, et al. MU-TEIR: Traceable encrypted image retrieval in the multi-user setting[J]. IEEE Transactions on Services Computing, 2023, 16 (2): 1282- 1295.
|
| 21 |
DING G, GUO Y, ZHOU J, et al. Large-scale cross-modality search via collective matrix factorization hashing[J]. IEEE Transactions on Image Processing, 2016, 25 (11): 5427- 5440.
|
| 22 |
ZHU L, SONG J, YANG Z, et al. DAP 2 CMH: Deep adversarial privacy-preserving cross-modal hashing[J]. Neural Processing Letters, 2022, 54 (4): 2549- 2569.
|
| 23 |
HU S, ZHANG L, WANG Q, et al. Towards private and scalable cross-media retrieval[J]. IEEE Transactions on Dependable and Secure Computing, 2021, 18 (3): 1354- 1368.
|
| 24 |
GUO C, JIA J, JIE Y, et al. Enabling secure cross-modal retrieval over encrypted heterogeneous IoT databases with collective matrix factorization[J]. IEEE Internet of Things Journal, 2020, 7 (4): 3104- 3113.
|
| 25 |
POPA R,REDFIELD C,ZELDOVICH N,et al. CryptDB:Protecting confidentiality with encrypted query processing[C]//Proceedings of the Twenty-third ACM Symposium on Operating Systems Principles. 2011:85-100.
|
| 26 |
NAVEED M,KAMARA S,WRIGHT C. Inference attacks on property-preserving encrypted databases[C]//Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security. 2015:644-655.
|
| 27 |
PODDAR R,BOELTER T,POPA R A. Arx:An encrypted database using semantically secure encryption[J]. Proceedings of the VLDB Endowment,12(11):1664 - 1678.
|
| 28 |
KAMARA S,MOATAZ T. SQL on structurally-encrypted databases[C]//Proceedings of the Advances in Cryptology-ASIACRYPT,2018:149-180.
|
| 29 |
PRIEBE C,VASWANI K,COSTA M. EnclaveDB:A secure database using SGX[C]//Proceedings of the IEEE Symposium on Security and Privacy. S&P 2018. IEEE,2018:264-278.
|
| 30 |
ESKANDARIAN S,ZAHARIA M. ObliDB:Oblivious query processing for secure databases[J]. Proceedings of the VLDB Endowment,13(2):169-183.
|
| 31 |
ZHU J, CHENG K, LIU J, et al. Full Encryption: An end to end encryption mechanism in GaussDB[J]. Proceedings of the VLDB Endowment, 2021, 14 (12): 2811- 2814.
|
| 32 |
CAO W,ZHANG Y,YANG X,et al. Polardb serverless:A cloud native database for disaggregated data centers[C]//Proceedings of the 2021 International Conference on Management of Data. 2021:2477-2489.
|
| 33 |
ANTONOPOULOS P,ARASU A,SINGH K D,et al. Azure SQL database always encrypted[C]//Proceedings of the 2020 ACM SIGMOD International Conference on Management of Data. 2020:1511-1525.
|
| 34 |
DAUTERMAN E,RATHEE M,POPA R A,et al. Waldo:A private time-series database from function secret sharing[C]// Proceedings of the 2022 IEEE Symposium on Security and Privacy,S&P 2022. IEEE,2022:2450-2468.
|
| 35 |
LI R,WANG P,ZHU J,et al. Building fast and compact sketches for approximately multi-set multi-membership querying[C]//Proceedings of the 2021 International Conference on Management of Data. SIGMOD 2021,2021:1077-1089.
|
| 36 |
LAI S,PATRANABIS S,SAKZAD A,et al. Result pattern hiding searchable encryption for conjunctive queries[C]//Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. CCS 2018,2018:745-762.
|
| 37 |
SAGAN H. Space-filling curves[J].Springer-Verlag GmbH, 2014, 12(8):133–135.
|
| 38 |
LIU A, CHEN F. Privacy preserving collaborative enforcement of firewall policies in virtual private networks[J]. IEEE Transactions on Parallel and Distributed Systems, 2011, 22 (5): 887- 895.
|
| 39 |
JIN C,LI C,WANG Z,et al. Sketch-based image retrieval with a novel bovw representation[C]// Proceeding of the International Conference on Multimedia Modeling. Springer,2016:621-631.
|
| 40 |
SANTOS J, MOURA E, SILVA A, et al. Color and texture applied to a signature-based bag of visual words method for image retrieval[J]. Multimedia Tools and Applications, 2017, 76 (15): 16855- 16872.
|
| 41 |
GUO S,XU J,ZHANG C,et al. Imageproof:Enabling authentication for large-scale image retrieval[C]//Proceedings of the 2019 IEEE 35th International Conference on Data Engineering,ICDE 2019. IEEE,2019:1070-1081.
|
| 42 |
LIU S,QIAN S,GUAN Y,et al. Jointmodal distribution-based similarity hashing for largescale unsupervised deep cross-modal retrieval[C]//Proceeding of the 43rd International ACM SIGIR Conference on Research and Development in Information Retrieval,2020:1379-1388.
|
| 43 |
CHEON J,KIM D,KIM D,et al. Lattice-based secure biometric authentication for hamming distance[C]//Proceeding of the Information Security and Privacy:26th Australasian Conference,ACISP 2021,Virtual Event. Springer,2021:653-672.
|
/
| 〈 |
|
〉 |