首页> 外文期刊>Journal of Parallel and Distributed Computing >Shield: A stackable secure storage system for file sharing in public storage
【24h】

Shield: A stackable secure storage system for file sharing in public storage

机译:Shield:可堆叠的安全存储系统,用于在公共存储中共享文件

获取原文
获取原文并翻译 | 示例

摘要

With the increasing amount of personal data stored in public storage, users are losing control of their physical data, putting their data information at risk of theft or being compromised. Traditional secure storage systems either require users to completely trust the storage provider or impose the considerable burden of managing files on file owners; such systems are inapplicable in the practical cloud environment. This paper addresses these challenging problems by proposing a new secure system architecture and implementing a stackable secure storage system named Shield, in which a proxy server is introduced to be in charge of authentication and access control. We propose a new variant of the Merkle Hash Tree to support efficient integrity checking and file content update; further, we have designed a hierarchical key organization to achieve convenient keys management and efficient permission revocation. Shield supports concurrent write access by employing a virtual linked list; it also provides secure file sharing without any modification to the underlying file systems. A series of evaluations over various real benchmarks show that Shield causes about 7%~13% performance degradation when compared with eCryptfs but provides enhanced security for user's data.
机译:随着存储在公共存储中的个人数据数量的增加,用户正在失去对物理数据的控制,使他们的数据信息面临被盗或被破坏的风险。传统的安全存储系统要么要求用户完全信任存储提供者,要么给文件所有者带来管理文件的巨大负担。这样的系统不适用于实际的云环境。本文通过提出一种新的安全系统架构并实现一个名为Shield的可堆叠安全存储系统来解决这些具有挑战性的问题,在其中引入了代理服务器来负责身份验证和访问控制。我们提出了Merkle哈希树的新变体,以支持有效的完整性检查和文件内容更新;此外,我们设计了一个分层的密钥组织,以实现便捷的密钥管理和有效的权限撤销。 Shield通过使用虚拟链表支持并发写访问。它还提供了安全的文件共享,而无需对基础文件系统进行任何修改。对各种实际基准进行的一系列评估表明,与eCryptfs相比,Shield会导致大约7%〜13%的性能下降,但可为用户数据提供增强的安全性。

著录项

  • 来源
    《Journal of Parallel and Distributed Computing》 |2014年第9期|2872-2883|共12页
  • 作者

    Jiwu Shu; Zhirong Shen; Wei Xue;

  • 作者单位

    Department of Computer Science and Technology, Tsinghua University, Beijing 100084, China Tsinghua National Laboratory for Information Science and Technology, Beijing 100084, China;

    Department of Computer Science and Technology, Tsinghua University, Beijing 100084, China Tsinghua National Laboratory for Information Science and Technology, Beijing 100084, China;

    Department of Computer Science and Technology, Tsinghua University, Beijing 100084, China Tsinghua National Laboratory for Information Science and Technology, Beijing 100084, China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Storage system; Cryptographic controls; Keys management; Proxy server; Secure sharing; Permission revocation; Concurrent writes;

    机译:存储系统;密码控制;密钥管理;代理服务器;安全共享;权限撤销;并发写入;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号