RSS feed RSS: Events | News | Papers

PDSI News @ UCSC

PDSI Events @ UCSC

No upcoming events at this time.

Secure File and Storage Systems

Description

We are investigating the use of strong authentication, encryption, and other mechanisms to safeguard data stored in network-attached storage systems and long-term archival storage systems. Adding security to large storage systems presents a serious challenge to scalability that we are addressing with the use of aggregate capabilities. We are also exploring protocols to verify remote storage and formal verification of secure network-attached storage.

Status

We have integrated security into the Ceph prototype. Our approach to security in Ceph allows secure access by hundreds of thousands of clients to a single file spread across tens of thousands of object-based storage devices without taxing the metadata servers or any other part of the system. The prototype implementation we developed imposes only a 6–7% overhead on a metadata-heavy workload involving file opens spread across hundreds of clients. We next plan to investigate the potential for including encryption and other strong security measures in Ceph.

We are also implementing a secure long-term archival storage system, POTSHARDS, that does not rely on encryption, instead using secret splitting and approximate pointers to keep data hidden. The archival storage project page has more details on POTSHARDS.

Publications


Last modified 16 Oct 2007
Home | Research | People | Publications | Seminars | Sponsors
  Site powered by Django