• DocumentCode
    1908129
  • Title

    Capability based Secure Access Control to Networked Storage Devices

  • Author

    Factor, Michael ; Naor, D. ; Rom, E. ; Satran, J.

  • Author_Institution
    IBM Haifa Lab., Haifa
  • fYear
    2007
  • fDate
    24-27 Sept. 2007
  • Firstpage
    114
  • Lastpage
    128
  • Abstract
    Today, access control security for storage area networks (zoning and masking) is implemented by mechanisms that are inherently insecure, and are tied to the physical network components. However, what we want to secure is at a higher logical level independent of the transport network; raising security to a logical level simplifies management, provides a more natural fit to a virtualized infrastructure, and enables a finer grained access control. In this paper, we describe the problems with existing access control security solutions, and present our approach which leverages the OSD (Object-based Storage Device) security model to provide a logical, cryptographically secured, in-band access control for today´s existing devices. We then show how this model can easily be integrated into existing systems and demonstrate that this in-band security mechanism has negligible performance impact while simplifying management, providing a clean match to compute virtualization and enabling fine grained access control.
  • Keywords
    authorisation; storage area networks; capability based secure access control; networked storage device; object-based storage device security model; storage area network; Access control; Access protocols; Cryptography; Data security; Encapsulation; Image storage; Read only memory; Secure storage; Storage area networks; Virtual machining; access control; capability-based security protocol.; networked; security; storage; virtualization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Mass Storage Systems and Technologies, 2007. MSST 2007. 24th IEEE Conference on
  • Conference_Location
    San Diego, CA
  • Print_ISBN
    978-0-7695-3025-3
  • Type

    conf

  • DOI
    10.1109/MSST.2007.4367968
  • Filename
    4367968