大数据安全与隐私计算技术综述
网络出版日期: 2024-12-17
基金资助
国家自然科学基金(U20B2048,62202302)
版权
Review of big data security and privacy computing technologies
Online published: 2024-12-17
Copyright
在数字化转型的浪潮中,数据已成为改变个人生活方式、驱动企业决策、提高公共服务质量的重要资源,其商业和社会价值不断提升。但与此同时,数据泄露、滥用和隐私侵犯的问题也愈加突出。随着大数据在各个领域的深度应用,如何在保障用户隐私的前提下充分挖掘数据价值已成为学术界和产业界关注的焦点。为了应对这些挑战,大数据安全与隐私保护技术迅猛发展,隐私计算作为其中的关键技术,已成为解决大数据安全与隐私保护矛盾的重要方式。在此背景下,回顾了数据安全的发展阶段,讨论了大数据安全面临的主要威胁及未来大数据安全能力建设的方向。在隐私计算方面,介绍了其基本概念、技术路线和前沿成果,并对其在应用中面临的挑战进行了探讨。对数据安全与隐私计算发展历程及最新技术进行综述,旨在为未来的研究提供参考,促进大数据安全与隐私保护技术的进一步发展与应用。
李建华 , 银鹰 , 李思源 , 林夕 . 大数据安全与隐私计算技术综述[J]. 网络空间安全科学学报, 2024 , 2(6) : 1 -15 . DOI: 10.20172/j.issn.2097-3136.240601
In the era of digital transformation, data has become a critical resource for reshaping the individual lifestyles, driving the corporate decision-making, and enhancing the public services, with its commercial and societal value steadily increasing. However, the risks of data leakage, misuse, and privacy invasion have also intensified. As big data integrates more deeply in various fields, how to extract the data value under the premise of protecting user’s privacy has become a central focus for both academia and industry. In response to these challenges, the data security and privacy protection technologies have advanced rapidly, as a key technology of which, privacy computing can offer effective solutions to the tension between secure data collaboration and privacy protection. In this context, the development stages of big data security were reviewed, and the major threats to data security and the future direction of building data security capacity were discussed. The basic concepts, technical routes and research efforts of the privacy computing were presented and the challenges faced in its application were also discussed. The overview of the development history and latest technologies of data security and privacy computing was to provide reference for the future research and to promote the further development and application of the big data security and privacy protection technologies.
| 1 |
李瑞轩, 董新华, 辜希武, 等. 移动云服务的数据安全与隐私保护综述[J]. 通信学报, 2013, 34 (12): 158- 166.
LI R X, DONG X H, GU X W, et al. Overview of the data security and privacy-preserving of mobile cloud services[J]. Journal on Communications, 2013, 34 (12): 158- 166.
|
| 2 |
FENG Q, HE D, ZEADALLY S, et al. A survey on privacy protection in blockchain system[J]. Journal of Network and Computer Applications, 2019, 126, 45- 58.
|
| 3 |
LEE D,KOHLBRENNER D,SHINDE S,et al. Keystone:an open framework for architecting trusted execution environments[C]//Proceedings of the 15th European Conference on Computer Systems. ACM,2020:1-16.
|
| 4 |
熊平, 朱天清, 王晓峰. 差分隐私保护及其应用[J]. 计算机学报, 2014, 37 (1): 101- 122.
XIONG P, ZHU T Q, WANG X F. A survey on differential privacy and applications[J]. Chinese Journal of Computers, 2014, 37 (1): 101- 122.
|
| 5 |
肖雄, 唐卓, 肖斌, 等. 联邦学习的隐私保护与安全防御研究综述[J]. 计算机学报, 2023, 46 (5): 1019- 1044.
XIAO X, TANG Z, XIAO B, et al. A survey on privacy and security issues in federated learning[J]. Chinese Journal of Computers, 2023, 46 (5): 1019- 1044.
|
| 6 |
李凤华,李晖,牛犇,等. 数据要素流通与安全的研究范畴与未来发展趋势[J]. 通信学报,2024,45(5):1-11.
LI F H ,LI H,NIU B,et al. Research category and future development trend of data elements circulation and security[J]. Journal on Communications,2024,45(5):1-11.
|
| 7 |
YANG P, XIONG N, REN J. Data security and privacy protection for cloud storage: a survey[J]. IEEE Access, 2020, 8, 131723- 131740.
|
| 8 |
ALTHONAYAN A,ANDRONACHE A. Shifting from information security towards a cybersecurity paradigm[C]//Proceedings of the 2018 10th International Conference on Information Management and Engineering. ACM,2018:68-79.
|
| 9 |
MOUSA A,KARABATAK M,MUSTAFA T. Database security threats and challenges[C]//2020 8th International Symposium on Digital Forensics and Security (ISDFS). IEEE,2020:1-5.
|
| 10 |
KOO J, KANG G, KIM Y G. Security and privacy in big data life cycle: a survey and open challenges[J]. Sustainability, 2020, 12 (24): 10571.
|
| 11 |
NAGHIZADEH P,SINHA A. Adversarial contract design for private data commercialization[C]//Proceedings of the 2019 ACM Conference on Economics and Computation. ACM,2019:681-699.
|
| 12 |
SUBASHINI S, KAVITHA V. A survey on security issues in service delivery models of cloud computing[J]. Journal of Network and Computer Applications, 2011, 34 (1): 1- 11.
|
| 13 |
郭华东. 科学大数据——国家大数据战略的基石[J]. 中国科学院院刊, 2018, 33 (8): 768- 773.
GUO H D. Scientific big data-a footstone of national strategy for big data[J]. Bulletin of Chinese Academy of Sciences, 2018, 33 (8): 768- 773.
|
| 14 |
覃庆玲, 彭志艺, 李晓伟. 全球数字经济浪潮下数据安全保护体系[J]. 信息安全与通信保密, 2020, 15 (2): 67- 81.
QIN Q L, PENG Z Y, LL X W. Data security protection system in the wave of global digital economy[J]. Information Security Communications Privacy, 2020, 15 (2): 67- 81.
|
| 15 |
阙天舒, 王子玥. 数字经济时代的全球数据安全治理与中国策略[J]. 国际安全研究, 2022, 40 (1): 130- 154.
QUE T S, WANG Z Y. Global data security governance and action strategies for China’s participation in the era of digital economy[J]. Journal of International Security Studies, 2022, 40 (1): 130- 154.
|
| 16 |
YU S,CARROLL F. Implications of AI in national security:understanding the security issues and ethical challenges[M]//Artificial Intelligence in Cyber Security:Impact and Implications:Security Challenges,Technical and Ethical Issues,Forensic Investigative Challenges. Cham:Springer International Publishing,2022.
|
| 17 |
MICHELI M,PONTI M,CRAGLIA M,et al. Emerging models of data governance in the age of datafication[J]. Big Data & Society,2020,7(2):2053951720948087.
|
| 18 |
郑志明, 何积丰, 唐立新, 等. 隐私计算的关键理论与前沿应用[J]. 中国科学基金, 2024, 38 (4): 603- 611.
ZHENG Z M, HE J F, TANG L X, et al. Innovative theoretical methods and key applications of privacy computing[J]. Bulletin of National Natural Science Foundation of China, 2024, 38 (4): 603- 611.
|
| 19 |
LI F, LI H, NIU B, et al. Privacy computing: concept, computing framework, and future development trends[J]. Engineering, 2019, 5 (6): 1179- 1192.
|
| 20 |
EVANS D, KOLESNIKOV V, ROSULEK M. A pragmatic introduction to secure multi-party computation[J]. Now Publishers, Norwell, MA, 2018, 2 (2-3): 70- 246.
|
| 21 |
GRPPERT T, DEML S, STURZENEGGER D, et al. Trusted execution environments: applications and organizational challenges[J]. Frontiers in Computer Science, 2022, 4, 930741.
|
| 22 |
ZHAO Y, CHEN J. A survey on differential privacy for unstructured data content[J]. ACM Computing Surveys, 2022, 54 (10s): 1- 28.
|
| 23 |
DO Q, BEN M, CHOO K K. The role of the adversary model in applied security research[J]. Computers & Security, 2019, 81, 156- 181.
|
| 24 |
ZHAO C, ZHAO S, ZHAO M, et al. Secure multi-party computation: theory, practice and applications[J]. Information Sciences, 2019, 476, 357- 372.
|
| 25 |
ACAR A, AKSU H, ULUAGAC A S, et al. A survey on homomorphic encryption schemes: theory and implementation[J]. ACM Computing Surveys, 2019, 51 (4): 1- 35.
|
| 26 |
ELGAMAL T. A public key cryptosystem and a signature scheme based on discrete logarithms[J]. IEEE Transactions Information Theory, 1985, 31 (4): 469- 472.
|
| 27 |
BLAZE M,BLEUMER G,STRAUSS M. Divertible protocols and atomic proxy cryptography[C]//International Conference on the Theory and Applications of Cryptographic Techniques. Berlin,Heidelberg:Springer ,1998:127-144.
|
| 28 |
ZHANG L, ZOU Y, WANG W, et al. Resource allocation and trust computing for blockchain-enabled edge computing system[J]. Computers & Security, 2021, 105, 102249.
|
| 29 |
ABERA T,ASOKAN N,DAVI L,et al. Invited-things,trouble,trust:on building trust in IoT systems[C]// Proceedings of the 53rd Annual Design Automation Conference. ACM,2016:1-6.
|
| 30 |
MOFRAD S,ZHANG F,LU S,et al. A comparison study of intel SGX and AMD memory encryption technology[C]//Proceedings of the 7th International Workshop on Hardware and Architectural Support for Security and Privacy. ACM,2018:1-8.
|
| 31 |
MUNOZ A, RIOS R, ROMAN R, et al. A survey on the (in) security of trusted execution environments[J]. Computers & Security, 2023, 129, 103180.
|
| 32 |
BARBOSA M,PORTELA B,SCERRI G,et al. Foundations of hardware-based attested computation and application to SGX[C]//2016 IEEE European Symposium on Security and Privacy (EuroS&P). IEEE,2016:245-260.
|
| 33 |
HAN S,JANG J. MyTEE:own the trusted execution environment on embedded devices[C]//Prceedings of the 30th Annual Network and Distributed System Security (NDSS). 2023.
|
| 34 |
LI S,LIN X,LI G,et al. DPG-DT:differentially private generative digital twin for imbalanced learning in industrial IoT[C]//19th International Conference on Mobility,Sensing and Networking (MSN). IEEE,2023:270-276.
|
| 35 |
WEN J, ZHANG Z, LAN Y, et al. A survey on federated learning: challenges and applications[J]. International Journal of Machine Learning and Cybernetics, 2023, 14 (2): 513- 535.
|
| 36 |
CAI X, GENG S, ZHANG J, et al. A sharding scheme-based many-objective optimization algorithm for enhancing security in blockchain-enabled industrial internet of things[J]. IEEE Transactions on Industrial Informatics, 2021, 17 (11): 7650- 7658.
|
| 37 |
CAO X,GONG N Z. Mpaf:model poisoning attacks to federated learning based on fake clients[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. IEEE,2022:3396-3404.
|
| 38 |
TAO Y, CUI S, XU W, et al. Byzantine-resilient federated learning at edge[J]. IEEE Transactions on Computers, 2023, 72 (9): 2600- 2614.
|
| 39 |
MUTHUKRISHNAN G, KALYANI S. Grafting Laplace and Gaussian distributions: a new noise mechanism for differential privacy[J]. IEEE Transactions on Information Forensics and Security, 2023, 18, 5359- 5374.
|
| 40 |
NANAYAKKARA P,SMART M A,CUMMINGS R,et al. What are the chances? Explaining the epsilon parameter in differential privacy[C]//32nd USENIX Security Symposium (USENIX Security 23).USENIX Associaton,2023:1613-1630.
|
| 41 |
ZHAO Y, DU J T, CHEN J. Scenario-based adaptations of differential privacy: a technical survey[J]. ACM Computing Surveys, 2024, 56 (8): 1- 39.
|
| 42 |
XU G W, LI H W, LIU S, et al. VerifyNet: secure and verifiable federated learning[J]. IEEE Transactions on Information Forensics and Security (TIFS), 2019, 15, 911- 926.
|
| 43 |
ZHANG Z B, DONG D J, MA Y H, et al. Refiner: a reliable incentive-driven federated learning system powered by blockchain[J]. Proceedings of the VLDB Endowment (PVLDB), 2021, 14 (12): 2659- 2662.
|
| 44 |
WARNAT-HERRESTHAL S, SCHULTZE H, SHASTRY K L, et al. Swarm learning for decentralized and confidential clinical machine learning[J]. Nature, 2021, 594 (7862): 265- 270.
|
| 45 |
何蒲, 于戈, 张岩峰, 等. 区块链技术与应用前瞻综述[J]. 计算机科学, 2017, 44 (4): 1- 7.
HE P, YU G, ZHANG Y F, et al. Survey on blockchain technology and its application prospect[J]. Computer Science, 2017, 44 (4): 1- 7.
|
| 46 |
MAESA D D F,MORI P,RICCI L. Blockchain based access control. In distributed applications and interoperable systems[C]//Proceedings of the 17th International Federated Conference on Distributed Computing Techniques,DisCoTec. Springer Nature Link,2022:206-220.
|
| 47 |
MAJEED U,HONG C S. FLchain:federated learning via MEC-enabled blockchain network[C]//In Proceedings of the 2019 20th Asia-Pacific Network Operations and Management Symposium (APNOMS). IEEE,2019:1-4.
|
| 48 |
TOLMACH P, LI Y, LIN S W, et al. A survey of smart contract formal specification and verification[J]. ACM Computing Surveys, 2021, 54 (7): 1- 38.
|
| 49 |
WANG J, LIN X, WU Y, et al. Blockchain-enabled lightweight fine-grained searchable knowledge sharing for intelligent IoT[J]. IEEE Internet of Things Journal, 2023, 10, 21566- 21579.
|
| 50 |
LU Y, HUANG X, DAI Y. et al. Blockchain and federated learning for privacy-preserved data sharing in industrial IoT[J]. IEEE Transactions on Industrial Informatics, 2020, 16, 4177- 4186.
|
| 51 |
LI Y, CHEN C, LIU N, et al. Blockchain-based decentralized federated learning framework with committee consensus[J]. IEEE Network, 2021, 35, 234- 241.
|
| 52 |
SYED N F, SHAH S W, SHAGHAGHI A, et al. Zero trust architecture (ZTA): a comprehensive survey[J]. IEEE Access, 2022, 10, 57143- 57179.
|
| 53 |
GE Y, ZHU Q. Gazeta: game-theoretic zero-trust authentication for defense against lateral movement in 5G IoT networks[J]. IEEE Transactions on Information Forensics and Security, 2024, 19, 540- 554.
|
| 54 |
RAFIQUE W, QI L, YAQOOB I, et al. Complementing IoT services through software defined networking and edge computing: a comprehensive survey[J]. IEEE Communications Surveys & Tutorials, 2020, 22 (3): 1761- 1804.
|
/
| 〈 |
|
〉 |