Block-Level Security for Network-Attached Disks

نویسندگان

  • Marcos K. Aguilera
  • Minwen Ji
  • Mark Lillibridge
  • John MacCormick
  • Erwin Oertli
  • David G. Andersen
  • Michael Burrows
  • Timothy Mann
  • Chandramohan A. Thekkath
چکیده

We propose a practical and efficient method for adding security to network-attached disks (NADs). In contrast to previous work, our design requires no changes to the data layout on disk, minimal changes to existing NADs, and only small changes to the standard protocol for accessing remote block-based devices. Thus, existing NAD file systems and storage-management software could incorporate our scheme very easily. Our design enforces security using the well-known idea of self-describing capabilities, with two novel features that limit the need for memory on secure NADs: a scheme to manage revocations based on capability groups, and a replay-detection method using Bloom filters. We have implemented a prototype NAD file system, called Snapdragon, that incorporates our ideas. We evaluated Snapdragon’s performance and scalability. The overhead of access control is small: latency for reads and writes increases by less than 0.5 ms (5%), while bandwidth decreases by up to 16%. The aggregate throughput scales linearly with the number of NADs (up to 7 in our experiments).

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Flexible Security for the WiND Filesystem

Due to the unending increase in scalability and performance demands, the network attached storage paradigm is being adopted as the solution for large storage systems. This new shift seeks to decentralize storage elements over a network where the idea is to transfer data directly between the storage disks and client machines thereby completely bypassing the fileserver machine bottleneck. The new...

متن کامل

A Case for Network-Attached Secure Disks (CMU-CS-96-142)

By providing direct data transfer between storage and client, network-attached storage devices have the potential to improve scalability (by removing the server as a bottleneck) and performance (through network striping and shorter data paths). Realizing the technology’s full potential requires careful consideration across a wide range of file system, networking and security issues. To address ...

متن کامل

A Case for Network-Attached Secure Disks

By providing direct data transfer between storage and client, network-attached storage devices have the potential to improve scalability (by removing the server as a bottleneck) and performance (through network striping and shorter data paths). Realizing the technology’s full potential requires careful consideration across a wide range of file system, networking and security issues. To address ...

متن کامل

SPIRAL: A Client-Transparent Third-Party Transfer Scheme for Network Attached Disks

Third-party transfer is a data transfer mechanism where the party initiating the transfer is neither the source nor the sink for the data. In this paper, we present a scheme for supporting third-party transfers on storage systems with network-attached disks (NADs), called SPIRAL 1. SPIRAL allows NADs to send data directly to clients without going through the server. It is transparent to clients...

متن کامل

Active Disks: A Scenario For Cost-effective Massive Data Processing

By providing direct data transfer between storage and client, networkattached storage devices have the potential to improve scalability for existing distributed file systems (by removing the server as a bottleneck) and bandwidth for parallel and distributed file systems (through network striping and more efficient data paths). Together, these advantages influence a large enough fraction of the ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2003