%0 Conference Proceedings %T GOOSE: A Secure Framework for Graph Outsourcing and SPARQL Evaluation %+ Sécurité des Données et des Systèmes (SDS) %+ Laboratoire d'Informatique Fondamentale d'Orléans (LIFO) %+ Institut National des Sciences Appliquées - Centre Val de Loire (INSA CVL) %+ Laboratoire d'Informatique, de Modélisation et d'Optimisation des Systèmes (LIMOS) %+ Université Clermont Auvergne [2017-2020] (UCA [2017-2020]) %A Ciucanu, Radu %A Lafourcade, Pascal %Z Online conference due to the coronavirus crisis %< avec comité de lecture %B 34th Annual IFIP WG 11.3 Working Conference on Data and Applications Security and Privacy (also known as DBSEC) %C Conférence online, Germany %P 347-366 %8 2020-06-25 %D 2020 %R 10.1007/978-3-030-49669-2_20 %K Unions of Conjunctions of Regular Path Queries %K Secure SPARQL Evaluation %K Secure Graph Outsourcing %K Honest-but-Curious Cloud %Z Computer Science [cs]/Databases [cs.DB] %Z Computer Science [cs]/Cryptography and Security [cs.CR]Conference papers %X We address the security concerns that occur when outsourcing graph data and query evaluation to an honest-but-curious cloud i.e., that executes tasks dutifully, but tries to gain as much information as possible. We present GOOSE, a secure framework for Graph OutsOurcing and SPARQL Evaluation. GOOSE relies on cryptographic schemes and secure multi-party computation to achieve desirable security properties: (i) no cloud node can learn the graph, (ii) no cloud node can learn at the same time the query and the query answers, and (iii) an external network observer cannot learn the graph, the query, or the query answers. As query language, GOOSE supports Unions of Conjunctions of Regular Path Queries (UCRPQ) that are at the core of the W3C’s SPARQL 1.1, including recursive queries. We show that the overhead due to cryptographic schemes is linear in the input’s and output’s size. We empirically show the scalability of GOOSE via a large-scale experimental study. %G English %L hal-02544920 %U https://inria.hal.science/hal-02544920 %~ PRES_CLERMONT %~ CNRS %~ UNIV-ORLEANS %~ LIMOS %~ IFIP-LNCS %~ IFIP %~ IFIP-TC %~ IFIP-WG %~ IFIP-TC11 %~ IFIP-WG11-3 %~ IFIP-DBSEC %~ INSA-GROUPE %~ INSA-CVL %~ TEST-HALCNRS %~ IFIP-LNCS-12122 %~ CLERMONT-AUVERGNE-INP %~ TEST3-HALCNRS