• DocumentCode
    2922295
  • Title

    Security Scheme for Sensitive Data in Management-Type SaaS

  • Author

    Xu, Jing ; Jinglei, Tang ; Dongjian, He ; Yang, Zhang

  • Author_Institution
    Coll. of Mech. & Electron. Eng., Northwest A&F Univ., YangLing, China
  • Volume
    4
  • fYear
    2009
  • fDate
    26-27 Dec. 2009
  • Firstpage
    47
  • Lastpage
    50
  • Abstract
    In this paper, we proposed the potential security problem of sensitive data in management-type SaaS which have no valid evidence when service provider embezzling or responsibility confirmation in service level agreement dispute, and proposed a scheme to ensure sensitive data safety by taking advantage of encryption and signature technique. Non-credible PKG of identity-based signature mechanism is used as signature mechanism for sensitive data in the scheme. Based on non-credible PKG of identity-based signature, a double-layer PKG framework is built by using the sub-PKG of service provider and tenants according to characteristic of the security responsibility of sensitive data is supervised by both service provider and tenants which have ownership and use right of the software respectively. The symmetric cryptography which ensures confidentiality of sensitive data is employed based on balance efficiency and safety. The related questions are also discussed. Security and the feasibility analysis show that this scheme ensures the confidentiality, integrity and non-repudiation of sensitive data. It can also provide valid evidence for service level agreement dispute and impel the application and the development of management-type SaaS. The proposed scheme can be widely applied to interactive distributed system of sensitive data.
  • Keywords
    cryptography; digital signatures; software engineering; double layer PKG framework; encryption technique; sensitive data security; service level agreement; signature technique; software-as-a-service; symmetric cryptography; Application software; Conference management; Data engineering; Data security; Engineering management; Identity-based encryption; Information security; Innovation management; Network servers; Public key cryptography; Data Security; Identity-based Signature; Management-type SaaS; Sensitive Data; non-credible PKG;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Management, Innovation Management and Industrial Engineering, 2009 International Conference on
  • Conference_Location
    Xi´an
  • Print_ISBN
    978-0-7695-3876-1
  • Type

    conf

  • DOI
    10.1109/ICIII.2009.473
  • Filename
    5369710