【24h】

An NFSv4-Based Security Scheme for NAS

机译:基于NFSv4的NAS安全方案

获取原文
获取原文并翻译 | 示例

摘要

This paper presents a security scheme for network-attached storage based on NFSv4 frame. One novel aspect of our system is that it enhances NFSv4 to guarantee the security of storage. Another novel feature is that we develop new user authentication mechanism which outperforms Kerberos. It uses HMAC and the symmetric cryptography to provide the integrity and privacy of transmitted data. The system includes three essential procedures: authenticating user, establishing security context and exchanging data. Our scheme can protect data from tampering, eavesdropping and replaying attacks, and it ensures that the data stored on the device is copy-resistant and encrypted. In spite of this level of security, the scheme does not impose much performance overhead. Our experiments show that large sequential reads or writes with security impose performance expense by 10-20%, which is much less than some other security systems.
机译:本文提出了一种基于NFSv4帧的网络附加存储安全方案。我们系统的一个新颖方面是它增强了NFSv4以保证存储的安全性。另一个新颖的功能是,我们开发了优于Kerberos的新用户身份验证机制。它使用HMAC和对称加密技术来提供传输数据的完整性和保密性。该系统包括三个基本过程:对用户进行身份验证,建立安全上下文以及交换数据。我们的方案可以保护数据免受篡改,窃听和重放攻击,并确保存储在设备上的数据具有防复制和加密功能。尽管具有这种安全级别,该方案也不会增加太多性能开销。我们的实验表明,具有安全性的大型顺序读取或写入会造成10-20%的性能损失,这比其他一些安全系统要少得多。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号