Block-Level Security for Network-Attached Disks
نویسندگان
چکیده
We propose a practical and efficient method for adding security to network-attached disks (NADs). In contrast to previous work, our design requires no changes to the data layout on disk, minimal changes to existing NADs, and only small changes to the standard protocol for accessing remote block-based devices. Thus, existing NAD file systems and storage-management software could incorporate our scheme very easily. Our design enforces security using the well-known idea of self-describing capabilities, with two novel features that limit the need for memory on secure NADs: a scheme to manage revocations based on capability groups, and a replay-detection method using Bloom filters. We have implemented a prototype NAD file system, called Snapdragon, that incorporates our ideas. We evaluated Snapdragon’s performance and scalability. The overhead of access control is small: latency for reads and writes increases by less than 0.5 ms (5%), while bandwidth decreases by up to 16%. The aggregate throughput scales linearly with the number of NADs (up to 7 in our experiments).
منابع مشابه
Flexible Security for the WiND Filesystem
Due to the unending increase in scalability and performance demands, the network attached storage paradigm is being adopted as the solution for large storage systems. This new shift seeks to decentralize storage elements over a network where the idea is to transfer data directly between the storage disks and client machines thereby completely bypassing the fileserver machine bottleneck. The new...
متن کاملA Case for Network-Attached Secure Disks (CMU-CS-96-142)
By providing direct data transfer between storage and client, network-attached storage devices have the potential to improve scalability (by removing the server as a bottleneck) and performance (through network striping and shorter data paths). Realizing the technology’s full potential requires careful consideration across a wide range of file system, networking and security issues. To address ...
متن کاملA Case for Network-Attached Secure Disks
By providing direct data transfer between storage and client, network-attached storage devices have the potential to improve scalability (by removing the server as a bottleneck) and performance (through network striping and shorter data paths). Realizing the technology’s full potential requires careful consideration across a wide range of file system, networking and security issues. To address ...
متن کاملSPIRAL: A Client-Transparent Third-Party Transfer Scheme for Network Attached Disks
Third-party transfer is a data transfer mechanism where the party initiating the transfer is neither the source nor the sink for the data. In this paper, we present a scheme for supporting third-party transfers on storage systems with network-attached disks (NADs), called SPIRAL 1. SPIRAL allows NADs to send data directly to clients without going through the server. It is transparent to clients...
متن کاملActive Disks: A Scenario For Cost-effective Massive Data Processing
By providing direct data transfer between storage and client, networkattached storage devices have the potential to improve scalability for existing distributed file systems (by removing the server as a bottleneck) and bandwidth for parallel and distributed file systems (through network striping and more efficient data paths). Together, these advantages influence a large enough fraction of the ...
متن کامل