Online published: 2024-11-16
Copyright
The secure storage and retrieval of data are essential for the secure utilization of open big data. However, existing big data storage and retrieval systems struggle to update storage keys and cannot handle both secure storage and efficient retrieval of multi-modal data. To address the issue of storage key update, a storage key update mechanism based on nested encryption was proposed, which supports efficient non-decrypted key update to meet the requirement for regular key rotation in untrusted environments. To solve the problem of index volume expansion, a compressed encrypted multi-set query filter was proposed to support high-density ciphertext indexing of massive data. Aiming at multi-modal data retrieval on encrypted data, a cross-type ciphertext composite association retrieval algorithm was designed to support single-type and cross-type retrieval of multi-modal encrypted data such as text, spatial, and images. Based on the above technologies, a multi-modal encrypted database system was designed, which supported the separation of storage and computing and was compatible with the technical architecture of existing big data services. The existing big data platform can be upgraded through incremental deployment of microservices to ensure system scalability and efficiency. Experimental results show that the key update performance of the proposed storage key update mechanism improve by over 80% compared to the traditional re-encryption mechanism. Compared to the existing plaintext database system, the overall performance loss of the proposed multi-modal encrypted database system in terms of text, space, image, and cross-modal retrieval does not exceed 25%.
WANG Xiangyu , MA Xindi , LIANG Yanrong , HE Zhizhou , MA Jianfeng . Secure Storage and Retrieval System for Open Big Data[J]. Journal of Cybersecurity, 2024 , 2(3) : 13 -26 . DOI: 10.20172/j.issn.2097-3136.240302
表 1 加密数据库技术路线特性对比Table 1 Comparison of technical routes for encrypted databases |
| 技术路线 | 功能性 | 性能 | 部署难度 | 稳定性 |
| 基于密文检索 的加密数据库 | 中 | 中 | 低 | 高 |
| 难以支持跨模态检索 | 索引膨胀较大,检索效率较高 | 支持单服务器部署,无需可信硬件 | 仅需单服务器 实时在线 | |
| 基于可信执行环 境的加密数据库 | 高 | 高 | 中 | 中 |
| 支持任意检索 | 无索引膨胀,检索效率高 | 支持单服务器部署,需要可信硬件 | 需要服务器和 可信执行环境实时通信 | |
| 基于分布式信任 的加密数据库 | 高 | 中 | 高 | 低 |
| 理论上支持任意检索 | 索引膨胀较小,检索效率较高 | 需要多个非共谋服务器,无需可信硬件 | 需要所有非共谋服务器 实时在线通信 |
| 1 |
BONEH D,LEWI K,MONTGOMERY H,et al. Key homomorphic PRFs and their applications[C]//Proceedings of the Annual Cryptology Conference,2013:410-428.
|
| 2 |
BOYD C,DAVIES G T,GJØSTEEN K,et al. Fast and secure updatable encryption[C]// Proceedings of the Annual International Cryptology Conference,2020:464-493.
|
| 3 |
LEHMANN A,TACKMANN B. Updatable encryption with post-compromise security[C]// Proceedings of the Advances in Cryptology-EUROCRYPT 2018:37th Annual International Conference on the Theory and Applications of Cryptographic Techniques,2018:685-716.
|
| 4 |
BONEH D,ESKANDARIAN S,KIM S,et al. Improving speed and security in updatable encryption schemes[C]//Proceedings of Advances in Cryptology-ASIACRYPT 2020:26th International Conference on the Theory and Application of Cryptology and Information Security,2020:559-589.
|
| 5 |
SONG D X,WAGNER D,PERRIG A. Practical techniques for searches on encrypted data[C]//Proceeding of the 2000 IEEE Symposium on Security and Privacy. S&P 2000. IEEE,2000:44-55.
|
| 6 |
BONEH D,CRESCENZO G D,OSTROVSKY R,et al. Public key encryption with keyword search[J]. Eurocrypt 2004,2004.
|
| 7 |
GOLLE P,STADDON J,WATERS B. Secure conjunctive keyword search over encrypted data[C]//Proceeding of the Applied Cryptography and Network Security:Second International Conference,ACNS 2004,2004.
|
| 8 |
LI F, MA J, MIAO Y, et. al. A survey on searchable symmetric encryption[J]. ACM Computing Surveys, 2023, 56 (5): 1- 42.
|
| 9 |
LIANG Y, MA J, MIAO Y, et al. Privacy-preserving bloom filter-based keyword search over large encrypted cloud data[J]. IEEE Transactions on Computers, 2023, 72 (11): 3086- 3098.
|
| 10 |
WANG X, MA J, MIAO Y, et al. Privacy-preserving diverse keyword search and online pre-diagnosis in cloud computing[J]. IEEE Transactions on Services Computing, 2022, 15 (2): 710- 723.
|
| 11 |
WONG W,CHEUNG D,KAO B,et al. Secure kNN computation on encrypted databases[C]//Proceedings of the ACM SIGMOD International Conference on Management of Data,SIGMOD 2009,2009.
|
| 12 |
XU G, LI H, DAI Y, et al. Enabling efficient and geometric range query with access control over encrypted spatial data[J]. IEEE Transactions on Information Forensics and Security, 2018, 14 (4): 870- 885.
|
| 13 |
WANG F, ZHU H, HE G, et al. Efficient and privacy-preserving arbitrary polygon range query scheme over dynamic and time-series location data[J]. IEEE Transactions on Information Forensics and Security, 2023, 18, 3414- 3429.
|
| 14 |
GONG Z, LI J, LIN Y, et al. Efficient privacy-preserving geographic keyword boolean range query over encrypted spatial data[J]. IEEE Systems Journal, 2023, 17 (1): 455- 466.
|
| 15 |
WANG X, MA J, LIU X, et al. Forward/backward and content private DSSE for spatial keyword queries[J]. IEEE Transactions on Dependable and Secure Computing, 2023, 20 (4): 3358- 3370.
|
| 16 |
MIAO Y, YANG Y, LI X, et al. Efficient privacy-preserving spatial range query over outsourced encrypted data[J]. IEEE Transactions on Information Forensics and Security, 2023, 18, 3921- 3933.
|
| 17 |
TONG Q, MIAO Y, CHEN L, et al. VFIRM: Verifiable fine-grained encrypted image retrieval in multi-owner multi-user settings[J]. IEEE Transactions on Services Computing, 2022, 15 (6): 3606- 3619.
|
| 18 |
XIA Z, WANG L, TANG J, et al. A privacy-preserving image retrieval scheme using secure local binary pattern in cloud computing[J]. IEEE Transactions on Network Science and Engineering, 2021, 8 (1): 318- 330.
|
| 19 |
LI Y, MA J, MIAO Y, et al. DVREI: Dynamic verifiable retrieval over encrypted images[J]. IEEE Transactions on Computers, 2022, 71 (8): 1755- 1769.
|
| 20 |
YANG T, MA J, MIAO Y, et al. MU-TEIR: Traceable encrypted image retrieval in the multi-user setting[J]. IEEE Transactions on Services Computing, 2023, 16 (2): 1282- 1295.
|
| 21 |
DING G, GUO Y, ZHOU J, et al. Large-scale cross-modality search via collective matrix factorization hashing[J]. IEEE Transactions on Image Processing, 2016, 25 (11): 5427- 5440.
|
| 22 |
ZHU L, SONG J, YANG Z, et al. DAP 2 CMH: Deep adversarial privacy-preserving cross-modal hashing[J]. Neural Processing Letters, 2022, 54 (4): 2549- 2569.
|
| 23 |
HU S, ZHANG L, WANG Q, et al. Towards private and scalable cross-media retrieval[J]. IEEE Transactions on Dependable and Secure Computing, 2021, 18 (3): 1354- 1368.
|
| 24 |
GUO C, JIA J, JIE Y, et al. Enabling secure cross-modal retrieval over encrypted heterogeneous IoT databases with collective matrix factorization[J]. IEEE Internet of Things Journal, 2020, 7 (4): 3104- 3113.
|
| 25 |
POPA R,REDFIELD C,ZELDOVICH N,et al. CryptDB:Protecting confidentiality with encrypted query processing[C]//Proceedings of the Twenty-third ACM Symposium on Operating Systems Principles. 2011:85-100.
|
| 26 |
NAVEED M,KAMARA S,WRIGHT C. Inference attacks on property-preserving encrypted databases[C]//Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security. 2015:644-655.
|
| 27 |
PODDAR R,BOELTER T,POPA R A. Arx:An encrypted database using semantically secure encryption[J]. Proceedings of the VLDB Endowment,12(11):1664 - 1678.
|
| 28 |
KAMARA S,MOATAZ T. SQL on structurally-encrypted databases[C]//Proceedings of the Advances in Cryptology-ASIACRYPT,2018:149-180.
|
| 29 |
PRIEBE C,VASWANI K,COSTA M. EnclaveDB:A secure database using SGX[C]//Proceedings of the IEEE Symposium on Security and Privacy. S&P 2018. IEEE,2018:264-278.
|
| 30 |
ESKANDARIAN S,ZAHARIA M. ObliDB:Oblivious query processing for secure databases[J]. Proceedings of the VLDB Endowment,13(2):169-183.
|
| 31 |
ZHU J, CHENG K, LIU J, et al. Full Encryption: An end to end encryption mechanism in GaussDB[J]. Proceedings of the VLDB Endowment, 2021, 14 (12): 2811- 2814.
|
| 32 |
CAO W,ZHANG Y,YANG X,et al. Polardb serverless:A cloud native database for disaggregated data centers[C]//Proceedings of the 2021 International Conference on Management of Data. 2021:2477-2489.
|
| 33 |
ANTONOPOULOS P,ARASU A,SINGH K D,et al. Azure SQL database always encrypted[C]//Proceedings of the 2020 ACM SIGMOD International Conference on Management of Data. 2020:1511-1525.
|
| 34 |
DAUTERMAN E,RATHEE M,POPA R A,et al. Waldo:A private time-series database from function secret sharing[C]// Proceedings of the 2022 IEEE Symposium on Security and Privacy,S&P 2022. IEEE,2022:2450-2468.
|
| 35 |
LI R,WANG P,ZHU J,et al. Building fast and compact sketches for approximately multi-set multi-membership querying[C]//Proceedings of the 2021 International Conference on Management of Data. SIGMOD 2021,2021:1077-1089.
|
| 36 |
LAI S,PATRANABIS S,SAKZAD A,et al. Result pattern hiding searchable encryption for conjunctive queries[C]//Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. CCS 2018,2018:745-762.
|
| 37 |
SAGAN H. Space-filling curves[J].Springer-Verlag GmbH, 2014, 12(8):133–135.
|
| 38 |
LIU A, CHEN F. Privacy preserving collaborative enforcement of firewall policies in virtual private networks[J]. IEEE Transactions on Parallel and Distributed Systems, 2011, 22 (5): 887- 895.
|
| 39 |
JIN C,LI C,WANG Z,et al. Sketch-based image retrieval with a novel bovw representation[C]// Proceeding of the International Conference on Multimedia Modeling. Springer,2016:621-631.
|
| 40 |
SANTOS J, MOURA E, SILVA A, et al. Color and texture applied to a signature-based bag of visual words method for image retrieval[J]. Multimedia Tools and Applications, 2017, 76 (15): 16855- 16872.
|
| 41 |
GUO S,XU J,ZHANG C,et al. Imageproof:Enabling authentication for large-scale image retrieval[C]//Proceedings of the 2019 IEEE 35th International Conference on Data Engineering,ICDE 2019. IEEE,2019:1070-1081.
|
| 42 |
LIU S,QIAN S,GUAN Y,et al. Jointmodal distribution-based similarity hashing for largescale unsupervised deep cross-modal retrieval[C]//Proceeding of the 43rd International ACM SIGIR Conference on Research and Development in Information Retrieval,2020:1379-1388.
|
| 43 |
CHEON J,KIM D,KIM D,et al. Lattice-based secure biometric authentication for hamming distance[C]//Proceeding of the Information Security and Privacy:26th Australasian Conference,ACISP 2021,Virtual Event. Springer,2021:653-672.
|
/
| 〈 |
|
〉 |