A Data Masking Technique for Data Warehouses
Authors
Abstract
Data Warehouses (DWs) are the enterprise’s most valuable asset in what concerns critical business information, making them an appealing target for attackers. Packaged database encryption solutions are considered the best solution to protect sensitive data. However, given the volume of data typically processed by DW queries, the existing encryption solutions heavily increase storage space and introduce very large overheads in query response time, due to decryption costs. In many cases, this performance degradation makes encryption unfeasible for use in DWs. In this paper we propose a transparent data masking solution for numerical values in DWs based on the mathematical modulus operator, which can be used without changing user application and DBMS source code. Our solution provides strong data security while introducing small overheads in both storage space and database performance. Several experimental evaluations using the TPC-H decision support benchmark and a real-world DW are included. The results show the overall efficiency of our proposal, demonstrating that it is a valid alternative to existing standard encryption routines for enforcing data confidentiality in DWs.
Keywords
Data security, Data confidentiality, Data privacy, Encryption, Data masking, Data warehousing
Subject
Data Security
Conference
IDEAS 2011 - International Database Engineering & Applications Symposium, September 2011
PDF File