Corslet: A shared storage system keeping your data private

Corslet: A shared storage system keeping your data private
复制标题

DOI:
10.1007/s11432-011-4259-y
复制
发表时间:
2011-05
期刊:
Science China Information Sciences
影响因子:
--
通讯作者:
Wei Xue;J. Shu;Yang Liu;Mao Xue
Wei Xue;J. Shu;Yang Liu;Mao Xue
中科院分区:
其他
文献类型:
--
作者:
Wei Xue;J. Shu;Yang Liu;Mao Xue

文献摘要

被引文献

相似文献

随着数字数据的指数级增长,将数据存储在同一组织内部的共享分布式存储系统中变得越来越流行。在这种分布式共享存储系统中,普通用户通常没有对整个系统的控制权限,无法保证自己文件的数据存储和数据共享。为了解决这一问题,本文提出了一种新的系统架构,可以在不可信的共享存储和网络环境下有效地保护文件的存储和共享。基于这种架构,本文设计并实现了一个可堆叠的安全存储系统Corslet。Corslet可以直接在部署的底层存储系统上运行,无需修改,同时为用户数据带来端到端的机密性和完整性,以及有效的访问控制。对于个人用户来说,Corslet易于使用,并且不需要用户在本地维护或管理客户端机器上的任何密钥。Bonnie++和IOzone的基准测试结果表明,在大多数测试中,Corslet在NFS上的吞吐量可以达到本地NFS吞吐量的90%以上,证明Corslet可以在保持可接受的性能的同时为用户数据提供增强的安全性。
With the exponential growth of digital data, it is becoming more and more popular to store data in shared distributed storage systems inside the same organization. In such shared distributed storage systems, an ordinary user usually does not have the control permission over the whole system, and thus cannot secure data storage or data sharing of his own files. To solve this issue, this paper proposes a new system architecture to secure file storing and sharing efficiently over untrusted shared storage and network environments. Based on this architecture, this paper designs and implements a stackable secure storage system called Corslet. Corslet can run directly on deployed underlying storage systems without modification, while bringing end-to-end confidentiality and integrity as well as efficient access control for user data. For individual users, Corslet is easy to use, and does not require users to maintain or manage any keys on their client machines locally. The Bonnie++ and IOzone benchmark results show that the throughput of Corslet over NFS can achieve more than 90% of native NFS throughput in most tests, proving that Corslet can provide enhanced security for user data while maintaining acceptable performance.