<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Privacy-Preserving OLAP-based Monitoring of Data Streams: The PP-OMDS Approach (Discussion Paper)1</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Alfredo Cuzzocrea</string-name>
          <email>alfredo.cuzzocrea@dia.units.it</email>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Assaf Schuster</string-name>
          <email>assaf@cs.technion.ac.il</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Gianni Vercelli</string-name>
          <email>gianni.vercelli@unige.it</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Massimiliano Nolich</string-name>
          <email>mnolich@units.it</email>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Technion</institution>
          ,
          <addr-line>Haifa</addr-line>
          ,
          <country country="IL">Israel</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>University of Genoa</institution>
          ,
          <addr-line>Genoa</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>University of Trieste</institution>
          ,
          <addr-line>Trieste</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>In this paper, we propose PP-OMDS (Privacy-Preserving OLAPbased Monitoring of Data Streams), an innovative framework for supporting the OLAP-based monitoring of data streams, which is relevant for a plethora of application scenarios (e.g., security, emergency management, and so forth), in a privacy-preserving manner. The paper describes motivations, principles and achievements of the PP-OMDS framework, along with technological advancements and innovations. We also incorporate a detailed comparative analysis with competitive frameworks, along with a trade-off analysis.</p>
      </abstract>
      <kwd-group>
        <kwd>Privacy-Preserving OLAP over Data Streams</kwd>
        <kwd>OLAP-based Monitoring of Data Streams</kwd>
        <kwd>Privacy-Preserving OLAP-based Monitoring of Data Streams</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        The PP-OMDS (Privacy-Preserving OLAP-based Monitoring of Data Streams)
framework focuses the attention on the research challenge represented by models, techniques
and algorithms for supporting privacy-preserving OLAP-based monitoring of data
streams. The investigated research context includes and integrates three distinct
components, namely privacy-preserving OLAP (e.g., [
        <xref ref-type="bibr" rid="ref1 ref14">1,14</xref>
        ]), data stream monitoring (e.g.,
[
        <xref ref-type="bibr" rid="ref15 ref2">2,15</xref>
        ]), and privacy-preserving data stream monitoring (e.g., [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]). Even if some
sporadic works on supporting aggregate monitoring queries in a privacy-preserving
manner exist (e.g., [
        <xref ref-type="bibr" rid="ref4 ref5">4,5</xref>
        ]), the three related issues have not been investigated together under
the umbrella of a common framework specially focused to OLAP analysis (rather than
the underlying aggregate querying layer), which indeed defines a powerful reference
1Copyright © 2019 for the individual papers by the papers’ authors. Copying permitted for private
and academic purposes. This volume is published and copyrighted by its editors. SEBD 2019,
June 16-19, 2019, Castiglione della Pescaia, Italy
application scenario for a wide spectrum of emerging applications over data streams,
such as security (e.g., [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]) and emergency management (e.g., [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]).
      </p>
      <p>Starting from this main motivation, the PP-OMDS framework aims at introducing
models, techniques and algorithms for supporting privacy-preserving OLAP-based
monitoring of data streams, which is relevant for modern distributed environments such
as Clouds. This will fulfil actual limitations of state-of-the-art solutions that do not
address the relevant application scenario represented by using OLAP tools and
methodologies to support data stream monitoring in a privacy-preserving manner. Application
scenarios of the PP-OMDS are many-fold (e.g., security and emergency management).
Tangible results of the PP-OMDS framework in real-life applicative settings are
represented by relevant research and innovation advancements in the context of models,
techniques and algorithms for supporting privacy-preserving OLAP-based monitoring
of data streams, which represent the main “result” of the framework. It should be noted
that, nowadays, these topics play a critical role as they are “naturally” compliant with
the EU H2020 research framework under the topic Big Data.</p>
      <p>The methodology implemented within the PP-OMDS framework foresees a
multistep approach that comprises: (i) conceptual analysis and design of case studies and
related use cases showing in details how and according to which tasks
users/applications interact with the PP-OMDS framework; (ii) conceptual analysis and design of
models, techniques and algorithms for supporting privacy-preserving OLAP-based
monitoring of data streams, which provides a top-down overview of the different
PPOMDS framework’s components to be defined and (prototypically) implemented; (iii)
design of the OLAP-based models and related algorithms for supporting the monitoring
of data streams, which represents a more-detailed view of the activity (ii) specifically
focused on OLAP-analysis aspects of the PP-OMDS framework; (iv) design of the
privacy-preserving version of the OLAP-based models and related algorithms for
supporting the monitoring of data streams, which represents a further refinement of models and
algorithms defined by the activity (iii) but targeted to embedding privacy-preserving
aspects of the PP-OMDS framework in such models and algorithms; (v) integration of
the OLAP component and the privacy-preserving OLAP component, both oriented to
data stream monitoring, into the PP-OMDS framework, according to several alternative
computing models.</p>
      <p>The scientific contribution of the research carried-out by the PP-OMDS framework
is very high because state-of-the-art research, even though focused on the relevant
problem of privacy-preserving OLAP over static data, lacks of proposals that are
specifically focused on privacy-preserving OLAP over data streams, and, in addition to this,
there is not a specific integration with monitoring aspects, which, contrary to this, are
indeed very relevant for a wide spectrum of next generation data stream applications
and systems.</p>
      <p>Summarizing, the main research topics investigated by the PP-OMDS framework
are the following:
 models, techniques and algorithms for supporting OLAP-based monitoring
of data streams;
 models, techniques and algorithms for supporting the privacy-preserving
version of OLAP-based monitoring of data streams;
 integration of models, techniques and algorithms devised in the context of
the two previous topics/activities, according to several alternative
computing models.</p>
      <p>
        The paper describes motivations, principles and achievements of the PP-OMDS
framework, along with technological advancements and innovations. We also
incorporate a detailed comparative analysis with competitive frameworks, along with a
tradeoff analysis.
In the PP-OMDS framework, the main research focus is on the issue of supporting
privacy-preserving OLAP-based monitoring of data streams, which, has highlighted
above, is innovative in actual state-of-the-art research, and it is of relevant interest for
a wide spectrum of data stream applications (e.g., security [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], emergency management
[
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], and so forth). Figure 1 shows a typical application scenario for the PP-OMDS
framework. Here, a sensor network, composed by both sink nodes and sensor nodes
(e.g., [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]), produces sensor readings of kind 〈 ,  ,  〉 such that: (i)  is the absolute
identifier of the sensor node, (ii)  is the timestamp at which the sensor reading is
produced, (iii)  is the proper reading (i.e., the value). A privacy-preserving 2D
OLAPbased monitoring view  is interfaced to the sensor network directly, and it is used to
monitor the reading value variable  , based on a complex multidimensional data model
[
        <xref ref-type="bibr" rid="ref8 ref9">8,9</xref>
        ]. In the reference application scenario of Figure 1, the model introduces 
as the first dimension and  as the second dimension, respectively, and the measure
value is defined on top of a COUNT aggregate operator over a two-dimensional range
〈 1,  2〉, being  1 and  2 two one-dimensional ranges along  and  ,
respectively, which define the data cube cell. The variable is monitored via suitable aggregate
monitoring queries (e.g., [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]) over data cube cells that populate the OLAP view  .
      </p>
      <p>
        With reference to the so-delineated application scenario, a critical challenge relies
on effectively and efficiently computing the OLAP view  over sensor readings (i.e.,
streaming data), with the additional requirement that  must be computed in a
privacypreserving manner (e.g., [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] – for the static case, [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] – for the dynamic case), i.e. it
must preserve the privacy of data sources that originate the sensor readings. The OLAP
view  is meant for monitoring goals: when the COUNT-aggregated value of a data
cube cell   exceeds a fixed threshold  , then an event occurs and a suitable action
(trigger, respectively) is activated in order to modify the target monitored environment.
Obviously, the described application scenario is just an instance that represents even
more sophisticated multidimensional settings, where the privacy-preserving
OLAPbased monitoring view is characterized by multiple dimensions. It is worth to recognize
that the described application scenario well-describes a plethora of modern data stream
applications, ranging from event detection to complex monitoring queries support, from
near-duplicate detection over multimedia streams to anomaly detection, and so forth,
all with the innovative and challenging requirement of preserving the privacy of data
streams, under OLAP analysis requirements (e.g., [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]), with monitoring purposes,
being the latter the three main pillar of the PP-OMDS project.
      </p>
    </sec>
    <sec id="sec-2">
      <title>PP-OMDS Architecture and Main Functionalities</title>
      <p>stream acquisition phase; (ii) My SQL database server provides the
necessary data storage (even buffer-oriented) and management functionalities.
Data Stream Monitoring Server – The server devoted to the monitoring of
data streams, by implementing the algorithms proposed in the PP-OMDDS
framework. It fully interacts with the Data Stream OLAP Server and the
Data Stream Privacy-Preservation Server, respectively, in order to achieve
the overall privacy-preserving OLAP-based monitoring of data streams
pursued by the PP-OMDDS project. Technology used: Java programming
language; JBoss application server. In particular, JBoss provides the
necessary Java execution runtime environment for the Data Stream Monitoring
Component, which is the component that implements classes and functions
supporting the data stream monitoring phase.</p>
      <p>Data Stream OLAP Server – The server devoted to support OLAP over of
data streams, by implementing the algorithms proposed in the PP-OMDDS
framework. It fully interacts with the Data Stream Monitoring Server and
the Data Stream Privacy-Preservation Server, respectively, in order to
achieve the overall privacy-preserving OLAP-based monitoring of data
streams pursued by the PP-OMDDS project. Technology used: Java
programming language; JBoss application server, Mondrian OLAP server. In
particular: (i) JBoss provides the necessary Java execution runtime
environment for the OLAPing Data Stream Component, which is the
component that implements classes and functions supporting OLAP analysis over
data streams; (ii) Mondrian OLAP server provides the necessary
multidimensional data storage and management functionalities.</p>
      <p>Data Stream Privacy-Preservation Server – The server devoted to support
privacy-preserving management of data streams, by implementing the
algorithms proposed in the PP-OMDDS project. It fully interacts with the
Data Stream Monitoring Server and the Data Stream OLAP Server,
respectively, in order to achieve the overall privacy-preserving OLAP-based
monitoring of data streams pursued by the PP-OMDDS project. Technology
used: Java programming language; JBoss application server. In particular,
JBoss provides the necessary Java execution runtime environment for the
Privacy-Preserving Data Stream Management Component, which is the
component that implements classes and functions supporting the
privacypreserving data stream management phase.</p>
      <p>Analytics Server – The server devoted to support data stream analytics,
according to the privacy-preserving OLAP-based vision pursued by the
PPOMDS framework. Technology used: Java programming language; JBoss
application server; MySQL database server. In particular: (i) JBoss
provides the necessary Java execution runtime environment for the PP-OMDS
Analytics Component, which is the component that implements classes and
functions supporting the PP-OMDS analytics phase; (ii) My SQL database
server provides the necessary data storage (even buffer-oriented) and
management functionalities.
 Streaming Analytics Layer – The layer where streaming analytics
functionalities are finally implemented and delivered to the client
applications/users, based on specific analytics goals (e.g., emergency detection and
management, security, etc.). Technology used: arbitrary (at the output layer).</p>
      <p>The PP-OMDS framework exploits software and hardware solutions that are
currently available and completely technologically-feasible (even considering open-source
solutions, in the case of software). Indeed, looking at the hardware architecture of the
PP-OMDS framework, we identify an (hardware) architecture that makes use of
standard solutions for (i) collecting data streams, (ii) monitoring data streams, (iii)
aggregating data streams, (iv) providing privacy-preserving methods over data streams, and (v)
supporting OLAP-like query answering over data streams. All these components are
commonly delivered on top of well-known architectures composed by (i) data servers,
(ii) OLAP servers, (iii) application servers, (iv) client components (e.g., desktop
computers, laptops, mobile devices, etc.). As regards the software architecture of the
PPOMDS framework, we identify a (software) architecture populated by software
components that can be developed by means of standard high-level programming languages
(e.g., Java, C++, etc.) and standard data access and manipulation methods (e.g., JDBC,
ODBC, etc.). It should be noted that, for both the hardware architecture and the software
architecture of the PP-OMDS framework, the components to be developed adhere to
well-assessed and mature technologies (both hardware and software) that clearly make
the PP-OMDS framework completely-feasible. In addition to this, all the components
of the PP-OMDS framework are already Cloud-enabled, hence the framework can be
easily extended towards a Cloud-based application (hence, improving performance,
reliability and availability).
4</p>
    </sec>
    <sec id="sec-3">
      <title>Comparative Analysis with Competitive Frameworks</title>
      <p>The software product context of the PP-OMDS framework is represented by the wide
area of streaming analytics tools and systems, and, in particular, those devoted to
support stream monitoring. Nevertheless, it does not exist a solution that specifically
focuses on the relevant problem of supporting privacy-preserving, OLAP-based
monitoring of distributed data streams, as delineated by the PP-OMDS framework’s
motivations. This confirms to us the innovativeness of our proposal.</p>
      <p>In the following, we focus the attention on the specific block-founding problems that
characterizes the PP-OMDS framework. For what regards the basic distributed data
stream monitoring problem, some relevant tools and systems that are currently
available are the following ones:
 APAMA Streaming Analytics, from Software AG;
 Stream Computing, from IBM;
 Event Stream Processor, from SAP;
 Apache Spark, from Cloudera.</p>
      <p>For what regards both the basic OLAP analysis over data streams problem and the
basic privacy-preserving data stream management problem, there do not exist direct
tools and systems currently available, although vertical solutions on top of existing
streaming analytics platforms can be devised.</p>
      <p>The most critical limitation of competitor frameworks is represented by the fact that
they all adhere to a common deployment model, i.e. providing a general platform for
supporting data stream analytics. While on top of such (common) platform personalized
solutions can still be developed (via ad-hoc IDE and functional programming
environments), they do not focus on the specialized problem of supporting privacy-preserving
OLAP-based monitoring of distributed data streams, despite the relevance of this
problem and its target application scenarios (e.g., emergency management, security, and so
forth).</p>
      <p>On the other hand, developing personalized solutions on general-purpose streaming
analytics platforms poses critical challenges for what regards a wide spectrum of issues,
ranging from complexity overheads to (software) maintenance problems, from
heterogeneous data format integration issues to analytical front-end tools that are not focused
to the peculiarities of the target application (thus making the whole knowledge
discovery from big streaming data harder), and so forth. All these considerations clearly
suggest the adoption of an all-inside, self-contained analytical framework that, still being
focused on the specific goal of supporting privacy-preserving OLAP-based distributed
data stream monitoring, can be further specialized on particular, vertical application
settings (still falling in the reference technological area).</p>
      <p>In addition to this, the competitor frameworks do not provide an explicit support
neither to OLAP analysis tools over data streams neither to privacy-preserving data
stream management, making for them hard to follow the paradigms dictated by the
PPOMDS framework’s paradigms. Table 1 proposes a summary on the comparative
analysis of the competitor frameworks against the PP-OMDS framework, along the
abovediscussed parameters/functionalities.</p>
    </sec>
    <sec id="sec-4">
      <title>Conclusions</title>
      <p>In this paper, we propose have proposed PP-OMDS, an innovative framework for
supporting the OLAP-based monitoring of data streams, which is relevant for a plethora of
application scenarios (e.g., security, emergency management, and so forth), in a
privacy-preserving manner.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <given-names>R.</given-names>
            <surname>Agrawal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Srikant</surname>
          </string-name>
          , D. Thomas:
          <string-name>
            <surname>Privacy-Preserving</surname>
            <given-names>OLAP</given-names>
          </string-name>
          , SIGMOD, pp.
          <fpage>251</fpage>
          -
          <lpage>262</lpage>
          ,
          <year>2005</year>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <given-names>M.</given-names>
            <surname>Gan</surname>
          </string-name>
          , H. Dai:
          <article-title>Detecting and monitoring abrupt emergences and submergences of episodes over data streams</article-title>
          .
          <source>Information Systems</source>
          <volume>39</volume>
          :
          <fpage>277</fpage>
          -
          <lpage>289</lpage>
          ,
          <year>2014</year>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <given-names>C.</given-names>
            <surname>Dwork</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Pitassi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Naor</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.N.</given-names>
            <surname>Rothblum:</surname>
          </string-name>
          <article-title>Differential privacy under continual observation</article-title>
          ,
          <source>STOC</source>
          ,
          <year>2010</year>
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <given-names>E.</given-names>
            <surname>Shi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.-H. H.</given-names>
            <surname>Chan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.G.</given-names>
            <surname>Rieffel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Chow</surname>
          </string-name>
          ,
          <string-name>
            <surname>D.</surname>
          </string-name>
          <article-title>Song: Privacy-preserving aggregation of time-series data</article-title>
          ,
          <source>NDSS</source>
          ,
          <year>2011</year>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <given-names>L.</given-names>
            <surname>Fan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Xiong</surname>
          </string-name>
          .
          <article-title>Real-time aggregate monitoring with differential privacy</article-title>
          ,
          <source>CIKM</source>
          ,
          <year>2012</year>
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>J. Zhou</surname>
            ,
            <given-names>O.C.</given-names>
          </string-name>
          <string-name>
            <surname>Au</surname>
            , G. Zhai,
            <given-names>Y.Y.</given-names>
          </string-name>
          <string-name>
            <surname>Tang</surname>
            ,
            <given-names>X.</given-names>
          </string-name>
          <article-title>Liu: Scalable Compression of Stream Cipher Encrypted Images Through Context-Adaptive Sampling</article-title>
          .
          <source>IEEE Transactions on Information Forensics and Security</source>
          <volume>9</volume>
          (
          <issue>11</issue>
          ):
          <fpage>1857</fpage>
          -
          <lpage>1868</lpage>
          ,
          <year>2014</year>
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <given-names>A.</given-names>
            <surname>Cuzzocrea</surname>
          </string-name>
          <article-title>: Optimization issues of querying and evolving sensor and stream databases</article-title>
          .
          <source>Information Systems</source>
          <volume>39</volume>
          :
          <fpage>196</fpage>
          -
          <lpage>198</lpage>
          ,
          <year>2014</year>
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Gray</surname>
            <given-names>J.</given-names>
          </string-name>
          , et al. Data
          <string-name>
            <surname>Cube: A Relational Aggregation Operator Generalizing</surname>
          </string-name>
          Group-By,
          <article-title>Cross-Tab, and Sub-Totals</article-title>
          .
          <source>Data Mining and Knowledge Discovery</source>
          ,
          <volume>1</volume>
          (
          <issue>1</issue>
          ):
          <fpage>29</fpage>
          -
          <lpage>54</lpage>
          ,
          <year>1997</year>
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>A.</surname>
          </string-name>
          <article-title>Cuzzocrea: CAMS: OLAPing Multidimensional Data Streams Efficiently</article-title>
          .
          <source>DaWaK</source>
          , pp.
          <fpage>48</fpage>
          -
          <lpage>62</lpage>
          ,
          <year>2009</year>
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <given-names>A.</given-names>
            <surname>Bulut</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Koudas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Meka</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.K.</given-names>
            <surname>Singh</surname>
          </string-name>
          ,
          <string-name>
            <surname>D.</surname>
          </string-name>
          <article-title>Srivastava: Optimization Techniques for Reactive Network Monitoring</article-title>
          .
          <source>IEEE Trans. Knowl. Data Eng</source>
          .
          <volume>21</volume>
          (
          <issue>9</issue>
          ):
          <fpage>1343</fpage>
          -
          <lpage>1357</lpage>
          ,
          <year>2009</year>
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <given-names>A.</given-names>
            <surname>Cuzzocrea</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Russo</surname>
          </string-name>
          ,
          <string-name>
            <surname>D.</surname>
          </string-name>
          <article-title>Saccà: A Robust Sampling-Based Framework for Privacy Preserving OLAP</article-title>
          . DaWaK, pp.
          <fpage>97</fpage>
          -
          <lpage>114</lpage>
          ,
          <year>2008</year>
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12. A. Cuzzocrea:
          <article-title>Retrieving Accurate Estimates to OLAP Queries over Uncertain and Imprecise Multidimensional Data Streams</article-title>
          . SSDBM,
          <year>2011</year>
          , pp.
          <fpage>575</fpage>
          -
          <lpage>576</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <given-names>A.</given-names>
            <surname>Cuzzocrea</surname>
          </string-name>
          , E. Bertino:
          <article-title>Privacy Preserving OLAP over Distributed XML Data: A Theoretically-Sound Secure-Multiparty-Computation Approach</article-title>
          .
          <source>Journal of Computer and System Sciences</source>
          <volume>77</volume>
          (
          <issue>6</issue>
          ):
          <fpage>965</fpage>
          -
          <lpage>987</lpage>
          ,
          <year>2011</year>
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <given-names>A.</given-names>
            <surname>Cuzzocrea</surname>
          </string-name>
          ,
          <string-name>
            <surname>V.</surname>
          </string-name>
          <article-title>Russo: Privacy Preserving OLAP</article-title>
          and
          <string-name>
            <given-names>OLAP</given-names>
            <surname>Security</surname>
          </string-name>
          .
          <source>Encyclopedia of Data Warehousing and Mining</source>
          <year>2009</year>
          , pp.
          <fpage>1575</fpage>
          -
          <lpage>1581</lpage>
          ,
          <year>2009</year>
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <given-names>A.</given-names>
            <surname>Beimel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Nissim</surname>
          </string-name>
          ,
          <string-name>
            <surname>E. Omri.</surname>
          </string-name>
          <article-title>Distributed private data analysis: Simultaneously solving how and what</article-title>
          ,
          <source>CRYPTO</source>
          , pp.
          <fpage>451</fpage>
          -
          <lpage>468</lpage>
          ,
          <year>2008</year>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>