Title
Combining fragmentation and encryption to protect privacy in data storage
Abstract
The impact of privacy requirements in the development of modern applications is increasing very quickly. Many commercial and legal regulations are driving the need to develop reliable solutions for protecting sensitive information whenever it is stored, processed, or communicated to external parties. To this purpose, encryption techniques are currently used in many scenarios where data protection is required since they provide a layer of protection against the disclosure of personal information, which safeguards companies from the costs that may arise from exposing their data to privacy breaches. However, dealing with encrypted data may make query processing more expensive. In this article, we address these issues by proposing a solution to enforce the privacy of data collections that combines data fragmentation with encryption. We model privacy requirements as confidentiality constraints expressing the sensitivity of attributes and their associations. We then use encryption as an underlying (conveniently available) measure for making data unintelligible while exploiting fragmentation as a way to break sensitive associations among attributes. We formalize the problem of minimizing the impact of fragmentation in terms of number of fragments and their affinity and present two heuristic algorithms for solving such problems. We also discuss experimental results, comparing the solutions returned by our heuristics with respect to optimal solutions, which show that the heuristics, while guaranteeing a polynomial-time computation cost are able to retrieve solutions close to optimum.
Year
DOI
Venue
2010
10.1145/1805974.1805978
ACM Trans. Inf. Syst. Secur.
Keywords
DocType
Volume
privacy requirement,data collection,fragmentation,model privacy requirement,encryption,Combining fragmentation,sensitive association,privacy,personal information,encryption technique,privacy breach,data fragmentation,data storage,encrypted data,data protection
Journal
13
Issue
ISSN
Citations 
3
1094-9224
93
PageRank 
References 
Authors
2.79
16
6
Name
Order
Citations
PageRank
Valentina Ciriani142235.11
Sabrina De Capitani Di Vimercati23991350.57
S. Foresti3100464.12
Sushil Jajodia493751839.16
Stefano Paraboschi53590450.24
Pierangela Samarati67152785.82