摘要
DAAS(Database as a Service)模式以其管理便捷的特性受到大量组织机构的青睐,同时托管数据的安全也成了迫切需要解决的难题.数据加密对于外包数据的安全起着重要作用,这会降低数据查询效率,因此高效安全的密文查询成为解决数据机密性的突破口,然而,云计算环境下国内外针对DAAS模式密文查询的研究缺少攻击模式下对隐私的深度分析.针对该问题,该文提出了一种DAAS模式下基于隐私保护的桶划分算法.首先根据查询效率指标提出了一种基于遗传算法的桶划分方案;在此基础之上,针对查询的过程中隐私泄漏情况提出了信息泄露的隐私指标体系,并将该指标体系与查询效率进行结合,最后基于遗传算法的桶划分算法对隐私与效率的模型进行最优化,从而获得最优的桶划分方案来确保查询过程中的隐私与查询效率最优的平衡.该算法可以在提高范围查询精确度和系统效率的基础上,降低密文查询中隐私泄露的信息,从而提高云平台中隐私数据的可用性和隐私性.最后,为了验证文中所提方案的可行性,将文中的算法与目前采用的几种桶划分方案进行对比,发现文中的方案在查询精准度上以及在隐私的保护上均优于其他方案.
A large number of organizations and institutions have been attracted to the cloud platform for its features, such as convenient management. Thus, the security of the outsourced data become more and more important. Encryption is a useful approach to protecting the data, while the features of the encrypted data are vanished. To manage the data effectively, the efficient and secure ciphertext query approach is urgent. However, the existing ciphertext query technology fails to provide a deep analysis in privacy leakage under attack. To solve this problem, we propose a privacy-preserving bucket partition mechanism in Database as a Service (DAAS) model in cloud. First, this paper proposed a generation algorithm (GA) based bucked partition mechanism according to the query efficiency. Then this paper built a privacy index system for information disclosure during the query and combined the privacy index system with the query efficiency. Finally, this paper optimized the proposed model based on the GA to balance the privacy and the accuracy during the query. The algorithm maximized the query accuracy and efficiency, reduced the information leakage during the query, and consequently enhances the availability and privacy of sensitive data in cloud. To verify the effectiveness of the proposed mechanism, the comparison experiments of our proposed mechanism and other bucket partition mechanisms were done. The result shows that the proposed mechanism is superior to others.
出处
《计算机学报》
EI
CSCD
北大核心
2016年第2期429-440,共12页
Chinese Journal of Computers
基金
国家自然科学基金(61373169
61272453
61103219)
"十二五"国家科技支撑计划(2015BAK07B03)
华中师范大学中央高校基本科研业务费资助项目(CCNU15GF001
CCNU15A05010)资助~~
关键词
密文查询
桶划分
遗传算法
隐私指标
云计算
ciphertext query
bucket partition
genetic algorithms
privacy indicators
cloud computing