• DocumentCode
    2896557
  • Title

    A Private and Anonymous Data Repository Service

  • Author

    Trevathan, Jarrod ; Read, Wayne

  • Author_Institution
    eResearch Centre, James Cook Univ., Townsville, QLD, Australia
  • fYear
    2010
  • fDate
    12-14 April 2010
  • Firstpage
    442
  • Lastpage
    447
  • Abstract
    This paper describes a security problem involving an online data repository which acts as a proxy for multiple companies allowing their customers to perform online services (e.g., pay invoices). The repository´s host is trusted to honestly fulfil its duties in maintaining the data in a manner consistent with each companies´ required services. However, the information stored by the repository remains private in that the repository´s host cannot openly read any companies´ operational data, nor does it learn the identities of any companies´ customers. We contrast several approaches describing their viability for web deployment using existing technologies. This is a fundamentally new security problem with no established literature or clearly defined cryptographic solution. The project originated from a commercial attempt to design a secure online data archive that allows a customer to pay and view invoices online.
  • Keywords
    cryptography; database management systems; cryptographic solution; data archive security; data privacy; data repository service; Authentication; Communication system security; Companies; Cryptography; Data security; Database systems; Electronic commerce; Information security; Information technology; Privacy; Authentication; eCommerce; encryption;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Technology: New Generations (ITNG), 2010 Seventh International Conference on
  • Conference_Location
    Las Vegas, NV
  • Print_ISBN
    978-1-4244-6270-4
  • Type

    conf

  • DOI
    10.1109/ITNG.2010.108
  • Filename
    5501737