Authenticated storage using small trusted hardware

Authenticated storage using small trusted hardware
复制标题

使用小型可信硬件进行身份验证的存储

DOI:
--
复制
发表时间:
2013
期刊:
Cloud Computing Security Workshop
影响因子:
--
通讯作者:
S. Devadas
S. Devadas
中科院分区:
--
文献类型:
--
作者:
Hsin;Victor Costan;Nickolai Zeldovich;S. Devadas

文献摘要

被引文献

相似文献

将数据存储外包给第三方提供商的一个主要安全问题是验证数据的完整性和新鲜度。最先进的基于软件的方法要求客户端保持状态,不能立即检测分叉攻击,而在存储服务器上引入有限可信硬件(例如,单调计数器)的方法实现低吞吐量。本文提出了一种新的数据存储身份验证设计,使用一小块高性能可信硬件连接到不可信服务器上。所提出的设计比以前的设计实现了显着更高的吞吐量。服务器端可信硬件允许客户端在不保持任何可变客户端状态的情况下验证数据的完整性和新鲜度。我们的设计通过并行服务器端身份验证操作,并允许不受信任的服务器维护缓存和调度磁盘写入,同时强制执行精确的崩溃恢复和写入访问控制,从而实现高性能。
A major security concern with outsourcing data storage to third-party providers is authenticating the integrity and freshness of data. State-of-the-art software-based approaches require clients to maintain state and cannot immediately detect forking attacks, while approaches that introduce limited trusted hardware (e.g., a monotonic counter) at the storage server achieve low throughput. This paper proposes a new design for authenticating data storage using a small piece of high-performance trusted hardware attached to an untrusted server. The proposed design achieves significantly higher throughput than previous designs. The server-side trusted hardware allows clients to authenticate data integrity and freshness without keeping any mutable client-side state. Our design achieves high performance by parallelizing server-side authentication operations and permitting the untrusted server to maintain caches and schedule disk writes, while enforcing precise crash recovery and write access control.