DocumentCode
1351031
Title
Fighting Mallory the Insider: Strong Write-Once Read-Many Storage Assurances
Author
Sion, Radu ; Chen, Yao
Author_Institution
Network Security & Appl. Cryptography Lab., Stony Brook Univ., Stony Brook, NY, USA
Volume
7
Issue
2
fYear
2012
fDate
4/1/2012 12:00:00 AM
Firstpage
755
Lastpage
764
Abstract
We introduce a Write-Once Read-Many (WORM) storage system providing strong assurances of data retention and compliant migration, by leveraging trusted secure hardware in close data proximity. This is important because existing compliance storage products and research prototypes are fundamentally vulnerable to faulty or malicious behavior, as they rely on simple enforcement primitives that are ill-suited for their threat model. This is hard because tamper-proof processing elements are significantly constrained in both computation ability and memory capacity-as heat dissipation concerns under tamper-resistant requirements limit their maximum allowable spatial gate-density. We achieve efficiency by 1) ensuring the secure hardware is accessed sparsely, minimizing the associated overhead for expected transaction loads, and 2) using adaptive overhead-amortized constructs to enforce WORM semantics at the throughput rate of the storage server´s ordinary processors during burst periods. With a single secure coprocessor, on commodity x86 hardware, the architecture can support unlimited read throughputs and over 2500 write transactions per second.
Keywords
coprocessors; fault tolerant computing; security of data; storage management; write-once storage; Mallory; WORM semantics; adaptive overhead-amortized construction; associated overhead minimization; burst periods; close data proximity; compliance storage products; compliant migration; computation ability; data retention; enforcement primitives; expected transaction loads; faulty behavior; heat dissipation; malicious behavior; maximum allowable spatial gate-density; memory capacity; research prototypes; secure coprocessor; tamper-proof processing elements; tamper-resistant requirements; throughput rate; trusted secure hardware; unlimited read throughputs; write-once read-many storage assurances; write-once read-many storage system; x86 hardware; Cryptography; Grippers; Hardware; Heating; Servers; Software; Data security; secure storage;
fLanguage
English
Journal_Title
Information Forensics and Security, IEEE Transactions on
Publisher
ieee
ISSN
1556-6013
Type
jour
DOI
10.1109/TIFS.2011.2172207
Filename
6046131
Link To Document