首页> 外文期刊>Parallel and Distributed Systems, IEEE Transactions on >Authenticated Key Exchange Protocols for Parallel Network File Systems
【24h】

Authenticated Key Exchange Protocols for Parallel Network File Systems

机译:并行网络文件系统的认证密钥交换协议

获取原文
获取原文并翻译 | 示例

摘要

We study the problem of key establishment for secure many-to-many communications. The problem is inspired by the proliferation of large-scale distributed file systems supporting to multiple storage devices. Our work focuses on the current Internet standard for such file systems, i.e., parallel Network File System (pNFS), which makes use of Kerberos to establish parallel session keys between clients and storage devices. Our review of the existing Kerberos-based protocol shows that it has a number of limitations: (i) a metadata server facilitating key exchange between the clients and the storage devices has heavy workload that restricts the scalability of the protocol; (ii) the protocol does not provide forward secrecy; (iii) the metadata server generates itself all the session keys that are used between the clients and storage devices, and this inherently leads to key escrow. In this paper, we propose a variety of authenticated key exchange protocols that are designed to address the above issues. We show that our protocols are capable of reducing up to approximately 54 percent of the workload of the metadata server and concurrently supporting forward secrecy and escrow-freeness. All this requires only a small fraction of increased computation overhead at the client.
机译:我们研究用于安全的多对多通信的密钥建立问题。该问题是由于支持多个存储设备的大规模分布式文件系统的激增而引起的。我们的工作重点是针对此类文件系统的当前Internet标准,即并行网络文件系统(pNFS),该标准利用Kerberos在客户端和存储设备之间建立并行会话密钥。我们对现有的基于Kerberos的协议的审查显示,它具有许多局限性:(i)便于客户端和存储设备之间进行密钥交换的元数据服务器的工作量很大,从而限制了该协议的可伸缩性; (ii)协议不提供前向保密性; (iii)元数据服务器自行生成客户端和存储设备之间使用的所有会话密钥,这必然导致密钥托管。在本文中,我们提出了旨在解决上述问题的各种经过身份验证的密钥交换协议。我们证明了我们的协议能够减少多达约54%的元数据服务器的工作量,并同时支持前向保密性和无托管权。所有这些仅需要客户端增加计算开销的一小部分。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号