Simple dynamic key management in SQL randomization

  • Authors:
  • Serguei A. Mokhov;Jian Li;Lingyu Wang

  • Affiliations:
  • Faculty of Engineering and Computer Science, Concordia University, Montréal, Québec, Canada;Faculty of Engineering and Computer Science, Concordia University, Montréal, Québec, Canada;Faculty of Engineering and Computer Science, Concordia University, Montréal, Québec, Canada

  • Venue:
  • NTMS'09 Proceedings of the 3rd international conference on New technologies, mobility and security
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

This work presents a simple key management scheme for dynamic SQL randomization based on the approach of the SNMPv3 key generation. The original SQL randomization technique based on keyed randomization proxies lacks a mechanism for managing and updating cryptographic keys, which renders the technique vulnerable to the exposure or theft of the keys. Our scheme provides a practical solution to remove such a weakness in the SQL randomization technique. The idea was conceived during the course of implementation of the Java Data Security Framework (JDSF) as a part of a database security and privacy project.