Hierarchical Role-Based Access Control with Homomorphic Encryption for Database as a Service
Kamlesh Kumar Hingwe, S. Mary Saira Bhanu

TL;DR
This paper proposes a secure, hierarchical role-based access control system for cloud databases that uses homomorphic encryption to protect sensitive data and prevent privilege escalation and SQL injection.
Contribution
It introduces a novel role-based access control framework with homomorphic encryption for secure data management in untrusted cloud environments.
Findings
Protects data confidentiality and integrity using homomorphic encryption.
Prevents privilege escalation and SQL injection attacks.
Manages role hierarchy and session security effectively.
Abstract
Database as a service provides services for accessing and managing customers data which provides ease of access, and the cost is less for these services. There is a possibility that the DBaaS service provider may not be trusted, and data may be stored on untrusted server. The access control mechanism can restrict users from unauthorized access, but in cloud environment access control policies are more flexible. However, an attacker can gather sensitive information for a malicious purpose by abusing the privileges as another user and so database security is compromised. The other problems associated with the DBaaS are to manage role hierarchy and secure session management for query transaction in the database. In this paper, a role-based access control for the multitenant database with role hierarchy is proposed. The query is granted with least access privileges, and a session key is…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
