期刊文献+

基于组密钥服务器的加密文件系统的设计和实现 被引量:8

Design and Implementation of a Group Key Server-Based Cryptographic File System
下载PDF
导出
摘要 网络存储技术在方便数据共享的同时带来了新的安全隐患,加密文件系统通过密码学方法保证存储在不受用户直接控制的服务器上的文件数据的机密性和完整性.现有的针对共享加密文件系统的密钥管理方法不能同时满足安全性、灵活性和高效性的需求.该文提出了加密文件系统GKS-CFS.引入可信的组密钥服务器(GKS)集中管理文件加密密钥,GKS上可以实施灵活的访问控制策略.通过使用访问控制块和锁盒子,降低了对GKS的计算和存储需求,使之可以用硬件实现来增强安全性;通过文件数据的分块加密和密钥版本技术,降低了权限撤销的开销.作者在Lustre上实现了GKS-CFS的原型系统并进行了测试.测试结果表明,由于避免使用了公钥密码算法,和其他系统相比,GKS-CFS的普通文件操作中的密码学操作开销减少了一个数量级,顺序读写和随机文件操作的性能分别平均降低了42.0%和8.4%. Network storage techniques facilitate data sharing but also introduce new vulnerabilities. Cryptographic file systems provide the confidentiality and integrity of file data stored on servers that are not under users' direct control by cryptographic methods. The key management schemes for current shared cryptographic file systems cannot satisfy the security, flexibility and efficiency requirements simultaneously. This paper proposes a cryptographic file system called CKS CFS. A trusted Group Key Server (GKS) is introduced to manage file encryption keys in a centralized manner and to enable the employment of flexible access control policies. The computation and storage requirement for (;KS is reduced through the use of access control blocks and lockboxes so that the function of GKS can be implemented by hardware to provide strong security. The overhead of revocation is reduced by block granularity encryption and key versioning technique. The authors have implemented a prototype of GKS-CFS based on Luster and evalua ted its performance. Compared with other systems, the cryptographic cost in common file operations in GKS-CFS is reduced by an order of magnitude by avoiding the usage of public-key cryptography; Bonnie++ benchmark test shows that the performance of sequential read/write and random file operations are reduced on average by 42.0% and 8. 40/40 respectively.
出处 《计算机学报》 EI CSCD 北大核心 2008年第4期600-610,共11页 Chinese Journal of Computers
基金 国家自然科学基金(60473101) 国家“九七三”重点基础研究发展规划项目基金(2004CB318205) 新世纪优秀人才支持计划项目基金(NCET-05-0067)资助~~
关键词 加密文件系统 机密性 完整性 密钥管弹 防损硬件 cryptographic file system confidentiality integrity key management tamper-resistanthardware
  • 相关文献

参考文献11

  • 1Blaze M. A cryptographic file system for UNIX//Proceedings of the 1st ACM Conference on Communications and Computing Security. Fairfax, Virginia, USA, 1993: 9-16
  • 2Fu K. Group sharing and random access in cryptographic storage file system [Master dissertation]. Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, USA, 1999
  • 3Goh E, Shacham H, Modadugu N, Boneh D. SiRiUS: Securing remote entrusted storage//Proceedings of the 10th Network and Distributed Systems Security Symposium (NDSS'03). San Diego, California, USA, 2003: 131-145
  • 4Halcrow M A. eCryptfs: An enterprise-class cryptographic file system for Linux//Proceedings of the 2005 Linux Symposium. Ottawa, Canada, 2005:201-218
  • 5Hughes J P, Feist C J. Architecture of the secure file system//Proceedings of the 8th IEEE Symposium on Mass Storage Systems. San Diego, USA, 2001:277-290
  • 6Kallahalla M, Riedel E, Swaminathan R, Wang Q, Fu K. Plutus: Scalable secure file sharing on entrusted storage// Proceedings of the 2nd USENIX Conference on File and Storage Technologies (FAST' 03). San Francisco, CA, USA, 2003:29-42
  • 7Wright C P, Martino M C, Zadok E. Ncryptfs: A secure and convenient eryptographie file system//Proceedings of the USENIX Annual Technical Conference. San Antonio, Texas, USA, 2003:197-210
  • 8Merkle R C. A digital signature based on a conventional encryption function//Proceedings of Advanced in Cryptology- CRYPTO'87. LNCS293. Springer Verlag, 1988:369-378
  • 9Neumann B C, Ts'o T, Kerberos: An authentication service for computer networks, IEEE Communications, 1994, 32 (9) : 33-38
  • 10Zhu Y, Hu Y. SNARE: A strong security scheme for network-attached storage//Proceedings of the 22nd International Symposium on Reliable Distributed Systems (SRDS' 03). Florence, Italy, 2003:250-259

同被引文献42

  • 1张焕杰,杨寿保.基于BGP协议的IP黑名单分发系统[J].中国海洋大学学报(自然科学版),2008,38(S1):157-159. 被引量:3
  • 2陈砣,吕新.基于JSP的棉花施肥管理决策系统的设计与实现[J].农业工程学报,2009,25(3):124-129. 被引量:10
  • 3韩宗芬,杨志玲,储杰,涂旭平.一种用于网络安全系统的报警聚类与关联模型[J].计算机工程与科学,2005,27(10):8-9. 被引量:4
  • 4王莉,刘厚泉,刘迎春,陆亚萍.可定制办公自动化系统的设计与实现[J].计算机工程与设计,2006,27(11):2085-2087. 被引量:15
  • 5王建仑,李道亮,董金勇,等.施肥处理方法及系统:中国.200910085741.3[P].2009-11-18.
  • 6CHRISTINE C, PATRICK L.Implementations of Advisory System for the Solvent selection of Carbon Dioxide Removal Processes [J].Elsevier Science, 1997 (38) : 87-92.
  • 7卢志红,赵小敏,吴建富.作物施肥决策系统的研究[C]//首届全国测土配方施肥技术研讨会论文集.呼和浩特:全国农业技术推广服务中心.2006:38-41.
  • 8William Stallings.Cryptography and network secudty[M].3rd Ed.USA:Prentice Hall,2002.
  • 9Halcrow M A.eCryptfs:An enterprise-class cryptographic file system for Linux[C].Ottawa,Canada:Proceedings of the 2005 Linux Symposium,2005:201-218.
  • 10Butler R,Welch V.A national-scale authentication infrastruture[J].IEEE Computer,2000,33(12):60-66.

引证文献8

二级引证文献9

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部