Have a personal or library account? Click to login
OSSDIP: Open Source Secure Data Infrastructure and Processes Supporting Data Visiting Cover

OSSDIP: Open Source Secure Data Infrastructure and Processes Supporting Data Visiting

Open Access
|Feb 2022

Figures & Tables

Table 1

Secure Enclave Features.

Physical LevelDedicated Hardware co-Processors
System-wide Bus-Address Filters
Trusted Execution Environments
“Airlocks” with Two-Person Rules
Network LevelVirtual Private Networking
Time-based One-time Passwords
Encrypted Data Transfer
Workstation LevelRemote Desktop
Access Control
Data LevelEncryption (at rest)
Homomorphic Encryption
Pseudonymization
Anonymization
Differential Privacy
dsj-21-1381-g1.png
Figure 1

The multiple security layers in our reference implementation. Components in golden color contain sensitive data anytime, red bars are restricted firewall barriers. Dotted boxes denote physical servers on which nodes can be deployed or virtualized (the VPN Node and Gate Node can share a physical server).

dsj-21-1381-g2.png
Figure 2

The Analyst can visit sensitive data using e.g. RStudio through the windowing system from the Remote Desktop-VM. The screenshot contains sample data for visualization purposes.

dsj-21-1381-g3.png
Figure 3

Social architecture of OSSDIP, dotted arrows are tasks that the respective role performs on infrastructure components.

dsj-21-1381-g4.png
Figure 4

To import data into the infrastructure, the Data Owner must follow the Data Ingress process (steps that are relevant only when the Data Provider is different from the Data Owner are colored gray and marked with an asterisk *). We color the Data Node golden, since it contains sensitive data.

dsj-21-1381-g5.png
Figure 5

To visit data in the infrastructure, the Analyst must follow the Data Access process. Since the Data Node contains sensitive data, we color it golden.

Language: English
Submitted on: Aug 5, 2021
|
Accepted on: Jan 4, 2022
|
Published on: Feb 9, 2022
Published by: Ubiquity Press
In partnership with: Paradigm Publishing Services
Publication frequency: 1 issue per year

© 2022 Martin Weise, Filip Kovacevic, Nikolas Popper, Andreas Rauber, published by Ubiquity Press
This work is licensed under the Creative Commons Attribution 4.0 License.