...
首页> 外文期刊>Parallel algorithms and applications >Integrating FPGA/ASIC into cryptographic storage systems to avoid re-encryption
【24h】

Integrating FPGA/ASIC into cryptographic storage systems to avoid re-encryption

机译:将FPGA / ASIC集成到密码存储系统中,以避免重新加密

获取原文
获取原文并翻译 | 示例
           

摘要

Almost all cryptographic storage systems need re-encryption when revoking users. These systems differ from each other only in the timing of re-encryption. As re-encryption is an expensive operation, it is significant to avoid re-encryption. To avoid re-encryption in cryptographic storage systems, field programmable gate array (FPGA) and application-specific integrated circuit (ASIC) hardware module have been integrated into encrypt-on-disk object store system in this paper, letting private key never leave the hardware module and object key existing only in hardware module in plaintext. Anyone who does not know private or object key, so when revoking usersjust needs to modify access control list (ACL) to delete the privileges of the users. To facilitate file sharing and key management, a group is adopted. In the system, almost all computationally expensive cryptographic operations are through FPGA/ASIC hardware module. Once a creator revokes some users, objects do not need re-encryption. How to use ACL and FPGA/ASIC hardware module to authenticate and authorise is also described. And the procedure of object store and the distribution of metadata are detailed. Finally, an encrypt-on-disk object store prototype system is implemented using FPGA in software solution with tested and effective performance.
机译:撤销用户时,几乎所有的密码存储系统都需要重新加密。这些系统仅在重新加密的时间上彼此不同。由于重新加密是一项昂贵的操作,因此避免重新加密非常重要。为了避免在密码存储系统中进行重新加密,本文将现场可编程门阵列(FPGA)和专用集成电路(ASIC)硬件模块集成到磁盘加密对象存储系统中,以使私钥永远不会离开密钥库。硬件模块和对象密钥仅以纯文本形式存在于硬件模块中。任何不知道私钥或对象密钥的人,因此在撤消用户时仅需要修改访问控制列表(ACL)即可删除用户的特权。为了促进文件共享和密钥管理,采用了一个组。在系统中,几乎所有计算量大的加密操作都是通过FPGA / ASIC硬件模块进行的。一旦创建者撤消了某些用户,对象就不需要重新加密。还描述了如何使用ACL和FPGA / ASIC硬件模块进行身份验证和授权。详细介绍了对象存储的过程和元数据的分配。最后,在软件解决方案中使用FPGA实现了磁盘加密对象存储原型系统,该系统具有经过测试和有效的性能。

著录项

  • 来源
    《Parallel algorithms and applications》 |2010年第2期|105-122|共18页
  • 作者单位

    School of Computer Science and Technology, Huazhong University of Science and Technology,Wuhan National Laboratory for Optoelectronics, Wuhan, P. R. China;

    rnSchool of Computer Science and Technology, Huazhong University of Science and Technology,Wuhan National Laboratory for Optoelectronics, Wuhan, P. R. China;

    rnSchool of Computer Science and Technology, Huazhong University of Science and Technology,Wuhan National Laboratory for Optoelectronics, Wuhan, P. R. China;

    rnSchool of Computer Science and Technology, Huazhong University of Science and Technology,Wuhan National Laboratory for Optoelectronics, Wuhan, P. R. China;

    rnSchool of Computer Science and Technology, Huazhong University of Science and Technology,Wuhan National Laboratory for Optoelectronics, Wuhan, P. R. China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    cryptographic file system; storage system; encryption; access control; FPGA; ASIC;

    机译:密码文件系统;存储系统;加密;访问控制;FPGA;专用集成电路;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号