首页> 外文会议>International Conference on Communications, Circuits and Systems >A Credential-based Security Mechanism for Object-based Storage
【24h】

A Credential-based Security Mechanism for Object-based Storage

机译:基于凭据基于对象存储的安全机制

获取原文

摘要

Unlike Direct Attached Storage (DAS), Network Attached Storage (NAS) or Storage Area Network (SAN), Object-based Storage, an emerging network storage technology, separates the control path, the data path and the management path, and enables direct interaction between clients and the storage devices. Clients acquire only the metadata information and some cryptographic primitives from the metadata servers. The Clients, the metadata servers and the storage devices are separate, so it is very important to construct a security mechanism for securing data exchange between them. In this paper we present a credential-based security mechanism for Object-based Storage that stands on existing security infrastructure. In this mechanism, the Object-based Storage Device (OSD) security model is a credential-based access control system, and commands transfer and data access both need be authorized. The Client requests a credential including a capability key from the Security Manager after authenticated by the Security Manager through a PKI system. The Security Manager and the OSD Device (OBSD) have a shared secret key to calculate the capability key which is used as a single secret key to identify the integrity of credential and encrypt the communications between the Client and the OBSD.
机译:与直接附加存储(DAS)不同,网络附加存储(NAS)或存储区域网络(SAN),基于对象的存储,新兴网络存储技术,将控制路径,数据路径和管理路径分开,并实现直接交互客户端和存储设备之间。客户端仅从元数据服务器获取元数据信息和一些加密原语。客户端,元数据服务器和存储设备是分开的,因此构建用于保护它们之间的数据交换的安全机制非常重要。在本文中,我们介绍了一种基于凭据的安全机制,用于站在现有的安全基础架构上。在这种机制中,基于对象的存储设备(OSD)安全模型是基于凭证的访问控制系统,并且需要授权命令传输和数据访问。客户端通过PKI系统通过PKI系统通过安全管理器进行认证后请求包括从安全管理器的功能密钥的凭证。安全管理器和OSD设备(OSD)具有共享密钥,以计算用作单个密钥的能力密钥,以确定凭证的完整性并加密客户端与obsd之间的通信。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号