CERIAS - Center for Education and Research in Information Assurance and Security

Skip Navigation
CERIAS Logo
Purdue University - Discovery Park
Center for Education and Research in Information Assurance and Security

Verification of Integrity for Outsourced Content Publishing and Database Queries

Danfeng Yao - Brown University

Oct 04, 2006

Size: 282.8MB

Download: Video Icon MP4 Video  
Watch in your Browser   Watch on Youtube Watch on YouTube

Abstract

In outsourced content publishing, the data owner gives the content to a service provider who answers requests from users. Similarly, in outsourced databases, the data owner delegates a service provider to answer queries. Outsourcing enables fast and fault-tolerant delivery of information. However, since service providers in outsourced systems may not be trusted by users, the user needs to verify the integrity of
information obtained.

First, I present a cryptographic solution for the verification of pseudonymized documents. A document can be pseudonymized by the service provider on the fly, based on the data owner's policies and the user's access permissions. Our pseudonym protocol is simple and efficient, and only requires the data owner to prepare and sign the document once.
Second, I present a solution for integrity verification of database aggregate queries, such as sum and max. We design proofs of correctness and completeness of aggregate results. What makes the problem challenging is that individual data entries may be sensitive (such as in medical databases), and should not be revealed to the user. We give
cryptographic protocols to support verification of query results in a privacy-preserving fashion.

About the Speaker

Danfeng Yao is a fifth-year graduate student in the Computer Science Department at Brown University, Providence, Rhode Island. She obtained her B.S degree from Peking University, China, and Master degrees from Princeton University and Indiana University at Bloomington. Her thesis research is focused on cryptographic protocols in
decentralized trust management, under the advising of Professor Roberto Tamassia. In the summer of 2006, Danfeng interned at HP Labs, Princeton, NJ. She worked closely with Stuart Haber, Bill Horne, and Tomas Sander on various aspects of the digital redaction project, which led to two HP technical reports. Danfeng's homepage is at http://www.cs.brown.edu/people/dyao/.

Unless otherwise noted, the security seminar is held on Wednesdays at 4:30P.M. STEW G52, West Lafayette Campus. More information...

Disclaimer

The views, opinions and assumptions expressed in these videos are those of the presenter and do not necessarily reflect the official policy or position of CERIAS or Purdue University. All content included in these videos, are the property of Purdue University, the presenter and/or the presenter’s organization, and protected by U.S. and international copyright laws. The collection, arrangement and assembly of all content in these videos and on the hosting website exclusive property of Purdue University. You may not copy, reproduce, distribute, publish, display, perform, modify, create derivative works, transmit, or in any other way exploit any part of copyrighted material without permission from CERIAS, Purdue University.