TL;DR: The first cloud-based RFID authentication protocol preserving tag/reader privacy to database keepers is proposed, which has advantages in deployment cost saving, pervasiveness of authentication, scalability of O(1) complexity to verify a tag, mobile reader holders' privacy preserving, and database security.
Abstract: Along with the development of cloud computing, cloud-based RFID is receiving more and more attentions of researchers and engineers. However, there is no research in which cloud computing is applied to RFID authentication schemes. Most current works lay emphasis on functionalities, lacking considerations about security and privacy. Classical RFID authentication schemes fail to meet the special security and privacy requirements of cloud-based RFID. The basic postulates of traditional backend-sever-based RFID authentication, i.e. secure backend channel and entirely trustworthy database, are no longer natively tenable in cloud-based RFID scenarios. In this paper, a virtual private network agency is suggested to build secure backend channels and to provide readers with anonymous access to the cloud. The cloud database is structured as an encrypted hash table. The first cloud-based RFID authentication protocol preserving tag/reader privacy to database keepers is proposed. Comparing with classical schemes, the proposed scheme has advantages in deployment cost saving, pervasiveness of authentication, scalability of O(1) complexity to verify a tag, mobile reader holders' privacy preserving, and database security.
TL;DR: A new approach for detecting intrusive attacks in databases by fusion of information sources and use of belief update is proposed and the system performs significantly better compared to two intrusion detection systems recently proposed in the literature.
Abstract: Insider threats have gained prominence and pose the most challenging threats to a database system. In this paper, we have proposed a new approach for detecting intrusive attacks in databases by fusion of information sources and use of belief update. In database intrusion detection, only intra-transactional features are not sufficient for detecting attackers within the organization as they are potentially familiar with the day-to-day work. Thus, the proposed system uses inter-transactional as well as intra-transactional features for intrusion detection. Moreover, we have also considered three different sensitivity levels of table attributes for keeping track of the malicious modification of the highly sensitive attributes more carefully. We have analyzed the performance of the proposed database intrusion detection system using stochastic models. Our system performs significantly better compared to two intrusion detection systems recently proposed in the literature.
TL;DR: In this article, the authors proposed a database security assessment method, consisting of an information collection module, an audit module, penetration testing module, trace processing module, assessment module and a system control module.
Abstract: The invention relates to a database security assessment method, belonging to the technical field of database security. In the method, the following modules are involved: (1) an information collection module, (2) an audit module, (3) a penetration testing module, (4) a trace processing module, (5) an assessment module and (6) a system control module. The system control module is implemented by the adoption of a programmable controller, is connected with other modules, and controls the operation and the data acquisition of each module. By the database security assessment method, a database security assessment report with reliability and security can be provided aiming at the problem that commercial vulnerability scanning tools hide test results in practical application, the current vulnerability risk level of the database is emphasized, the current security problems of the database are learnt by a database administrator intuitively, a security policy is completed, and security risks are lowered.
TL;DR: A comparison study between current methods in terms of performance and security is provided and some methods to deal directly with the encrypted data without firstly decrypting them are introduced.
Abstract: Using database encryption to protect data in some situations where access control is not solely enough is inevitable. Database encryption provides an additional layer of protection to conventional access control techniques. It prevents unauthorized users, including intruders breaking into a network, from viewing the sensitive data. As a result data keeps protected even in the incident that database is successfully attacked or stolen. However, data encryption and decryption process result in database performance degradation. In the situation where all the information is stored in encrypted form, one cannot make the selection on the database content any more. Data should be decrypted first, so an unwilling tradeoff between the security and the performance is normally forced. The appropriate approaches to increase the performance are methods to deal directly with the encrypted data without firstly decrypting them. This paper while introduce some methods for searching on encrypted data, provides a comparison study between current methods in terms of performance and security.
TL;DR: The aim of this study is to identify the risks and controls used in ERP database access, with the objective to understand the ways in which organizations can minimize the business risks involved.
Abstract: Database Security essentially refers to protection of the information content in database In general, the decision regarding who should be allowed access to the databases or alternatively who should be denied access to the database is dictated by the security policies of the organization concerned The implementation of ERP systems has been problematic for much organization because of one of the reason is lack of database security The aim of this study is to identify the risks and controls used in ERP database access, with the objective to understand the ways in which organizations can minimize the business risks involved In this paper are describe different types of vulnerability of database and Suggestions are offered in resolving the issues for database security in ERP system
TL;DR: In this article, a security access control method and a system of a database is presented, which comprises the steps of collecting a database access mode and database access log, analyzing the database access modes and access logs according to database access security elements.
Abstract: The invention provides a security access control method and a system of a database. The method comprises the steps of collecting a database access mode and a database access log, analyzing the database access mode and the database access log according to database access security elements, formatting SQL (Structured Query Language) statements in the analyzed database access mode and the database access log, collecting database security access request information input by a user, identifying the database security access request information according to the formatted database access mode and the database access log, and generating an identification result. According to the security access control method and the system, the security control of a database system is improved, and the data leakage caused by unauthorized data access due to imperfect authority monitoring in a data system is reduced.
TL;DR: C cumulative damage model to backup of files in a database system is applied, by putting damage shock by update, failure shock by database failure and damage by dumped files, and the tradeoff among overhead costs of image copy and incremental, full backup methods is considered.
Abstract: As the computer system has developed much in this highly information-oriented society, database security has become a very important problem and its backup strategies need to be made more efficiently and safety. The image copy method has been used as the most simple and dependable recovery mechanism for media failure. However, this method spends high overhead costs for massive data transmission and much processing time in the normal operation of the database. To cover such weak points, incremental and full backup methods are adopted before updated trucks reach a predetermined level. Moreover, when the number of full backup files exceeded a predetermined level, we stop incremental and full backups and switch it to the image copy. This paper applies cumulative damage model to backup of files in a database system, by putting damage shock by update, failure shock by database failure and damage by dumped files, and considers the tradeoff among overhead costs of image copy and incremental, full backup methods, and discusses analytically an optimal policy for the image copy backup interval. Finally, numerical examples are given in the case of Poisson process and exponential distributions.
TL;DR: QSB is not only an efficient example of query-based bucketization for DAS, but a conceptual model for future research, in which data are organized to accommodate a variety of query access patterns, thereby improving query efficiency and database security.
Abstract: Dr. Ray Kresman, Advisor An ongoing problem in Database As a Service (DAS) is how to increase the efficiency of retrieving encrypted data from remote untrusted servers without compromising security. Bucketization is a privacy–preserving technique for executing SQL queries over encrypted data on a DAS server. Bucketization partitions encrypted attributes into queryable tables (buckets), thereby disguising which records are requested. While a number of bucketization techniques are optimized for uniform query access, many Internet and private network access patterns reflect a non–uniform or Zipf-like trend. If query access is non-uniform, existing techniques may be subject to substantial performance degradation. In order to evaluate that possibility, this thesis presents new bucketization technique, Query Sensitive Bucketization (QSB), that capitalizes on the probability distribution of non-uniform queries. Two existing uniform bucketization techniques were implemented to (1) evaluate their performance when the distribution of queries is non–uniform, and (2) evaluate their performance relative to QSB. Among the measures used for performance analysis, a new security metric is presented, which quantifies the risk of an adversary estimating the true value distribution of an encrypted data store. Unlike existing security metrics, the new metric expresses information disclosed by the pattern of query access over an encrypted bucket set. Results showed that QSB improves query efficiency over uniform techniques, while maintaining a high level of data security. QSB is not only an efficient example of query-based bucketization for DAS, but a conceptual model for future research, in which data are organized to accommodate a variety of query access patterns, thereby improving query efficiency and database security.
TL;DR: In this article, an audio information-based database security access control method of digital watermark was proposed, which is characterized by comprising the following steps of: A watermark generating step: obtaining a speech signal of a user, converting the speech signal into a binary string to be combined with user right to generate a watermark; B watermark embedding step: embedding the watermark into a region for storing user information in a database; C watermark extraction step: extracting the watermarks, and by carrying out an inverse generation algorithm on the extracted watermark, extracting the
Abstract: The invention relates to an audio information-based database security access control method of digital watermark The control method is characterized by comprising the following steps of: A a watermark generating step: obtaining a speech signal of a user, converting the speech signal into a binary string to be combined with user right to generate a watermark; B a watermark embedding step: embedding the watermark into a region for storing user information in a database; C a watermark extraction step: extracting the watermark, and by carrying out an inverse generation algorithm on the extracted watermark, extracting the right value and initial speech of the user; and D a database authentication and access control step: calculating the eigenvalue of the initial speech obtained in the step C, and comparing with the eigenvalue of new speech provided by an access user; if the eigenvalues are the same, granting the right value extracted in the step C to the access user; if the eigenvalues are different, then enabling the access user to have no right to access the database According to the control method provided by the invention, biological characteristics are used for authentication and can not be lost, stolen or forgotten to prevent false use of right and provide protection for information security
TL;DR: In this article, a database firewall is deployed between a web server and a database, a query request sent to the database and a query result fed back from the database are intelligently processed, a security protection mechanism is provided in system environment deployment, and only a single port is opened to connect.
Abstract: The invention discloses a Web safety-oriented database security protection method and a Web safety-oriented database security protection system. A database firewall is deployed between a Web server and a database, a query request sent to the database and a query result fed back from the database are intelligently processed, a security protection mechanism is provided in system environment deployment, and only a single port is opened to connect. The security of the database is guaranteed by multiprocessing an input request and an output result through a firewall module, and meanwhile, security assurance for the database is added in a unique environment deploying way of the Web server.
TL;DR: Experimental results demonstrate the superiority of the proposed TSFS algorithm, as it has outperformed the well-established benchmark algorithms, DES and AES, in terms of query execution time and database added size.
Abstract: Virtually all of today’s organizations store their data in huge databases to retrieve, manipulate and share them in an efficient way. Due to the popularity of databases for storing important and critical data, they are becoming subject to an overwhelming range of threats, such as unauthorized access. Such a threat can result in severe financial or privacy problems, as well as other corruptions. To tackle possible threats, numerous security mechanisms have emerged to protect data housed in databases. Among the most successful database security mechanisms is database encryption. This has the potential to secure the data at rest by converting the data into a form that cannot be easily understood by unauthorized persons. Many encryption algorithms have been proposed, such as Transposition-Substitution-Folding-Shifting encryption algorithm (TSFS), Data Encryption Standard (DES), and Advanced Encryption Standard (AES) algorithms. Each algorithm has advantages and disadvantages, leaving room for optimization in different ways. This paper proposes enhancing the TSFS algorithm by extending its data set to special characters, as well as correcting its substitution and shifting steps to avoid the errors occurring during the decryption process. Experimental results demonstrate the superiority of the proposed algorithm, as it has outperformed the well-established benchmark algorithms, DES and AES, in terms of query execution time and database added size.
TL;DR: An enhanced model that increases the capability of RBAC model by integrating Auditing and Authentication in simplest ways is proposed, which not only provides the features ofRBAC but also handles common issues of database security.
Abstract: In past decade lot of research has been done in RBAC (Role Based Access Control) technology. The industries have also shown great interest in RBAC. Most of the IT vendors are offering products that incorporate some form of RBAC. Today, all major DBMS products support RBAC. RBAC provides easier management of permissions in an organization and hence is most widely used model to control access of legitimate users. However research shows that access control is not a complete solution for securing a database. Most of the breaches are done by insiders. So, access control system must be incorporated with other mechanisms that provide more features than just controlling access of users. Auditing is such a mechanism that can log all the transactions occurring on the database and based on this log an analysis can be done. Auditing is well effective when we have good authentication. Authentication processes are vulnerable to SQL Injection attacks. This paper proposes an enhanced model that increases the capability of RBAC model by integrating Auditing and Authentication in simplest ways. In this way this model not only provides the features of RBAC but also handles common issues of database security.
TL;DR: This paper analyzed the database queries and the data properties and proposed and analyzed the new database encryption algorithm using the Bloom Filter with the bucket index method and demonstrated the superiority of the proposed algorithm through several experiments.
Abstract: Database security techniques are available widely. Among those techniques, the encryption method is a well-certified and established technology for protecting sensitive data. However, once encrypted, the data can no longer be easily queried. The performance of the database depends on how to encrypt the sensitive data, and an approach for searching and retrieval efficiencies that are implemented. In this paper we analyze the database queries and the data properties and propose a suitable mechanism to query the encrypted database. We proposed and analyzed the new database encryption algorithm using the Bloom Filter with the bucket index method. Finally, we demonstrated the superiority of the proposed algorithm through several experiments that should be useful for database encryption related research and application activities.
TL;DR: This framework includes detection and sanitization of the tainted information being sent to the database and innovate a new prototype which is used to sanitize the users inputs that may transform into a database attack.
Abstract: With the increasing importance of the internet in our day-to-day life, data security in web application has become very crucial. Ever increasing online and real time transaction services have led to manifold rise in the problems associated with the database security. Attacker uses illegal and unauthorized approaches to hijack the confidential information like username, password and other vital details. Hence the real-time transaction requires security against web based attacks. SQL injection and cross site scripting attack are the most common application layer attack. The SQL injection attacker pass SQL statement through a web application's input fields, URL or hidden parameters and get access to the database or update it. The attacker take a benefit from user provided data in such a way that the user's input is handled as a SQL code. Using this vulnerability an attacker can execute SQL commands directly on the database. SQL injection attacks are most serious threats which take user's input and integrate it into SQL query. Reverse Proxy is a technique which is used to sanitize the users' inputs that may transform into a database attack. In this technique a data redirector program redirects the user's input to the proxy server before it is sent to the application server. At the proxy server, data cleaning algorithm is triggered using a sanitizing application. In this framework we include detection and sanitization of the tainted information being sent to the database and innovate a new prototype.
TL;DR: The specific requirements for a DW DIDS are defined and a conceptual approach for a real-time DIDS for DWs at the SQL command level that works transparently as an extension of the Database Management System between the user applications and the database server itself is proposed.
Abstract: Data Warehouses (DWs) are used for producing business knowledge and aiding decision support. Since they store the secrets of the business, securing their data is critical. To accomplish this, several Database Intrusion Detection Systems (DIDS) have been proposed. However, when using DIDS in DWs, most solutions produce either too many false-positives (i.e., false alarms) that must be verified or too many false-negatives (i.e., true intrusions that pass undetected). Moreover, many approaches detect intrusions a posteriori which, given the sensitivity of DW data, may result in irreparable cost. To the best of our knowledge, no DIDS specifically tailored for DWs has been proposed. This paper examines intrusion detection from a data warehousing perspective and the reasons why traditional database security methods are not sufficient to avoid intrusions. We define the specific requirements for a DW DIDS and propose a conceptual approach for a real-time DIDS for DWs at the SQL command level that works transparently as an extension of the Database Management System (DBMS) between the user applications and the database server itself. A preliminary experimental evaluation using the TPC-H decision support benchmark is included to demonstrate the DIDS’ efficiency.
TL;DR: In this paper, two fundamental approaches to protect sensitive rules from disclosure are that, preventing rules from being generated by hiding the frequent sets of data items and reducing the importance of the rules by setting their confidence below a user-specified threshold.
Abstract: ‘Data Mining’ is a way of extracting data or uncovering hidden patterns of information from databases. So, there is a need to prevent the “inference rules” from being disclosed such that the more secure data sets cannot be identified from non-sensitive attributes. This can be done through removing/adding certain item sets in the transactions (Sanitization). The purpose is to hide the Inference rules, so that the user may not be able to discover any valuable information from other non-sensitive data and any organisation can release all samples of their data without the fear of ‘Knowledge Discovery In Databases’ which can be achieved by investigating frequently occurring item sets, rules that can be mined from them with the objective of hiding them. Another way is to release only limited samples in the new database so that there is no information loss and it also satisfies the legitimate needs of the users. The major problem is uncovering hidden patterns, which causes a threat to the database security. Sensitive data are inferred from non-sensitive data based on the semantics of the application the user has, commonly known as the ‘inference problem’. Two fundamental approaches to protect sensitive rules from disclosure are that, preventing rules from being generated by hiding the frequent sets of data items and reducing the importance of the rules by setting their confidence below a user-specified threshold.
TL;DR: In this paper, a reverse proxy is used to sanitize the users inputs that may transform into a database attack, where a data redirector program redirects the users input to the proxy server before it is sent to the application server, data cleaning algorithm is triggered using a sanitizing application.
Abstract: With the increasing importance of the internet in our day to day life, data security in web application has become very crucial. Ever increasing on line and real time transaction services have led to manifold rise in the problems associated with the database security. Attacker uses illegal and unauthorized approaches to hijack the confidential information like username, password and other vital details. Hence the real time transaction requires security against web based attacks. SQL injection and cross site scripting attack are the most common application layer attack. The SQL injection attacker pass SQL statement through a web applications input fields, URL or hidden parameters and get access to the database or update it. The attacker take a benefit from user provided data in such a way that the users input is handled as a SQL code. Using this vulnerability an attacker can execute SQL commands directly on the database. SQL injection attacks are most serious threats which take users input and integrate it into SQL query. Reverse Proxy is a technique which is used to sanitize the users inputs that may transform into a database attack. In this technique a data redirector program redirects the users input to the proxy server before it is sent to the application server. At the proxy server, data cleaning algorithm is triggered using a sanitizing application. In this framework we include detection and sanitization of the tainted information being sent to the database and innovate a new prototype.
TL;DR: In this paper, a method for preventing the forgery of data in a database is provided to remarkably reduce a system load according to the application of database forgery prevention technology by generating a database security value with only the calculation of a hash value.
Abstract: PURPOSE: A method for preventing the forgery of data in a database is provided to remarkably reduce a system load according to the application of database forgery prevention technology by generating a database security value with only the calculation of a hash value. CONSTITUTION: A security key is generated and encoded as a server certificate to be stored. The encoded security key is decoded for system operation. When data is inserted into a user information database table, all attribute values in a database table line are connected with a character string(S36). A security addition character string is generated by additionally connecting the encoded security key with the character string. A hash value for the security addition character string is calculated(S37). The hash value is stored in the user information database table as a database security value(S38). [Reference numerals] (AA) Start; (BB) Security key; (CC) End; (S31) Generating a security key; (S32) Encoding and storing the security key with a server certificate; (S33) Decoding the security key; (S34) Storing in a DB table?; (S35) Connecting all attribute data of each row in the DB table with one character string; (S36) Additionally connecting the security key with the generated character string; (S37) Calculating a Hash value for the connected character string; (S38) Storing the Hash value as a DB security value
TL;DR: A hybrid authorization conflict detection method that combines the two methods and does not need to pre-analyze conflict conditions perfectly such as in the authorization-level method because RDF inference is conducted directly.
Abstract: Controlling access to the resource description framework (RDF) is complex and costly because of ontology inference. Jain and Farkas suggested an instance-level authorization conflict detection algorithm in consideration of this complexity. However, their method entails significant costs because security levels are assigned in all instances, and RDF inference is actually performed for the instances. To reduce costs, an authorization-level conflict detection method was proposed. The proposed method does not assign security levels to instances but evaluates judges if there is the existence of conflicts by only verifying access authorizations based on pre-analyzed authorization conflict conditions. However, this method is based on the assumption that authorization conflict conditions should be pre-analyzed completely. In this paper, we propose a hybrid authorization conflict detection method that combines the two methods. The hybrid method does not need to pre-analyze conflict conditions perfectly such as in the authorization-level method because RDF inference is conducted directly. However, given that the hybrid method does not have to consider all instances, the conflict detection time is shorter for the hybrid method than that for the instance-level method. Experimental results also indicate that the hybrid method is feasible.
TL;DR: This paper presents active multi-layer policies for securing relational database that lies on the server side, monitor authorized users who may misuse their privileges on the client side, and monitor database administrators who may use their multiple privileges to penetrate the security system.
Abstract: The security of database depends on a set of systems, roles, procedures, and processes that protect the entire database from unintended activities. Unintended activities can be categorized as authentic ated misuse, malicious attacks or inadvertent mistakes made by authorized users. If any intruder succeeds in attacking the system network, the database security will be the last line of defense in protecting confidentiality, availability, and integrity. This paper presents inte ractive multi-layer policies for securing relational database that lies on the server side, monitor authorized users who may misuse their privileges on the client side, and monitor database administrators who may use their multiple privileges to penetrate the security system. These multi-layer policies can be combined together to create a defense system that puts the intruder under pressure at all security levels in order to protect integrity and confidentiality of database.
TL;DR: This chapter describes issues of database design for databases that provide representations that allow rough set data and provides the various related rough normal forms used in a database schema design.
Abstract: This chapter describes issues of database design for databases that provide representations that allow rough set data. We first present the definition of a rough relational database. A database can be designed by Entity-Relationship modeling or by defining the functional dependencies for the system. We describe rough set E-R models and rough functional dependencies. Based on the rough functional dependencies we provide the various related rough normal forms used in a database schema design. Finally, we discuss issues of database security and the use of rough spatial data in a rough relational database.
TL;DR: This thesis work proposes and implements a new algorithm to provide privacy to sensitive data and shows that proposed algorithm is more efficient as it performs privacy preserving mining by pruning more rules.
Abstract: Efficient Privacy Preserving association rule mining has emerged as a latest research issue. In this thesis work, existing algorithms, Increase Support of Left Hand Side and Decrease Support of Right Hand Side are implemented successfully on the real data for Privacy Preserving Association Rule Mining. To provide privacy to sensitive data we also propose and implement a new algorithm .The performance of new algorithm is also compared with existing algorithms on the basis of number of rule pruned. The result show that proposed algorithm is more efficient as it performs privacy preserving mining by pruning more rules. Securing these against unauthorized access to the long-term goal of the database security research base community and the government statistical agencies. Whether data is personal or corporate data, data mining offers the potential to reveal what other regard as sensitive (private). In some cases, it may be of mutual benefit for two parties' even competitors to be share their data for analysis task. They would like to it will be ensure their own data remains private. In other good words, there is a need to protect sensitive knowledge during a data mining process. For Experimental work, we have used a realistic database of Doctor Patient Evaluation is taken from Medical College.
TL;DR: A Multi agent system which uses Artificial Neural Network algorithm, which helps to detect malicious SQL queries, which possesses a multi level architecture which uses multiple agents, where each level is assigned with some.
Abstract: This paper describes a Multi agent system which uses Artificial Neural Network algorithm, which helps to detect malicious SQL queries. As SQL injection queries are one of the most hazardous attacks for database security in today’s database system, this multi agent system is useful to catch SQL injection attacks. This system possesses a multi level architecture which uses multiple agents, where each level is assigned with some. The SQL injection attacks are one of the biggest security threats in databases. SQL injection is a technique used to take advantage of non-validated input vulnerabilities to pass SQL commands through a Web application for execution by a back-end database. This system checks each query rigorously and goes through idCBR cycle i.e case based reasoning is done which gives the output legal/illegal/suspicious.
TL;DR: The need for a database trigger and it role in enforcing the various database security challenges is explained and the role of the database trigger is explained.
Abstract: Database Security is a growing concern evidenced by an increase in the number of reported incidencesof loss of or unauthorized exposure to sensitive data. As the amount of data collected, retained and shared electronically expands, so does the need to understand database security. Security models, developed for databases differ in many aspects because they focus on different features of the database security problem or because they make different assumptions about what constitutes a secure database. This paper explains the need for a database trigger and it role in enforcing the various database security challenges.
TL;DR: A multi- layer approach to database anonymity based on a multi-layer security infrastructure is proposed that provides both static and dynamic means of securing sensitive data and focuses on securing the communication, the operating system and the database server.
Abstract: The evolution of computer technology renders servers, workstations, computers and even mobile devices more and more powerful. This leads to their increased use and storage of data. Data warehouses may contain large quantities of sensitive information. Therefore, data privacy is a very important aspect of data publishing. The best method for protecting data privacy is data anonymity. The use of anonymous data improves the degree of privacy provided by data warehouses. However, data anonymity alone is never enough for protecting the privacy of sensitive information, requiring database security also. In this paper we propose a multi-layer approach to database anonymity based on a multi-layer security infrastructure. From an anonymity perspective, we have developed an engine that provides both static and dynamic means of securing sensitive data. Also, the temporal aspect of a dynamic database in time leads to an alteration of possible inferences. Also, in this paper we focused on securing the communication, the operating system and the database server.
TL;DR: This paper studies the approach of using DML triggers to implement SQL Server referential integrity and designs the database logical structure and physical structure, and achieves deleting trigger and modifies trigger.
Abstract: Database integrity is an important research content of database security, triggers can enforce the more complex referential integrity, and this paper studies the approach of using DML triggers to implement SQL Server referential integrity. First, studies the working principle of DML triggers; Second, researches and creates DML triggers, focusing on explained the Transact-SQL creating parameters based on the illustration of DML triggers created; Finally, shows the achieve methods through many-many relationship examples, designs the database logical structure and physical structure, and achieves deleting trigger and modifies trigger. This content provides a concrete method to use the SQL Server database software development implement referential integrity, and it has broad application prospects.
TL;DR: The paper throw a light on various factors of security issues in 3- tier architecture while fetching data from various sources, issues related storing these data and retrieving these data.
Abstract: Database integrity has a major goal of maintaining the internal consistency of the data in the database. The database system is to maintain internal consistency volume, variety and velocity of data is observed by many users as the principal database security concern. These can be considered to be the minimal requirement for the database system to be used. Data are generated every minute from different source. These data need to be organized and secured for accurate and easy knowledge discovery. So this paper focuses on various security challenges of data in 3 - tier architecture in respect to data- warehouse. The paper throw a light on various factors of security issues in 3- tier architecture while fetching data from various sources, issues related storing these data and retrieving these data. The security problem not only exists in just OLAP that is while storing the data in data warehouse but its concern starts from very beginning when the fetching of data takes place .
TL;DR: A B-tree is used, which is a standard data structure for efficiently retrieving data from conventional databases, to develop a secret-shared B+tree that enables data retrieval from secret- shared databases with O(logm) time complexity while maintaining the security provided by secret sharing.
Abstract: Information revelations from databases may result not only from intrusions by external attackers but also from malicious actions by employees and even database administrators. A promising new approach to solving this problem is the use of secret-shared databases. In this approach, information is divided into unreadable snippets, and the snippets are stored in separate subdatabases, thereby making it difficult for external and internal attackers to steal the original information. A secret-shared database is secure unless k or more database administrators collude, where k is a predefined threshold. Any query that is executable for a conventional database is executable for the corresponding secret-shared database. However, retrieval (i.e., selection) of a record from a secret-shared database has a time complexity of O(m), where m is the number of records stored in the database. We used a B+tree, which is a standard data structure for efficiently retrieving data from conventional databases, to develop a secret-shared B+tree that enables data retrieval from secret-shared databases with O(logm) time complexity while maintaining the security provided by secret sharing.
TL;DR: The connotation of reference integrity is studied, the database example used in study of reference Integrity reference method is given, and various operating processing method of applications achieve reference integrity are studied.
Abstract: Database integrity is one of the important research content of database security,and reference integrity can ensure the validity of the contact between database table and table,and prevent the loss of data or the proliferation of meaningless data in the databaseFirst study the connotation of reference integrity,then give the database example used in study of reference integrity reference method,finally study the three methods of reference integrityThe first method is reference constraint,researches the operation processing method created reference relationship and reference relationship;the second method is trigger,researches the classification and function,the working principle and the means to achieve referential integrity with it;the third method is the application,researches various operating processing method of applications achieve reference integrity