Title :
An Implementation of Object-Based Storage System Access Control Based on IBE
Author :
Chen, Junjian ; Feng, Dan ; Liu, Jingning
Author_Institution :
Wuhan Nat. Lab. for Optoelectron., Huazhong Univ. of Sci. & Technol., Wuhan, China
Abstract :
Object-based Storage System (OBSS) is the ideal solution to improve performance of large-scale storage systems by virtue of distributed storage architecture. However, existing OBSS adopts complex security scheme, and takes little consideration on how to reduce the overhead of storage security. Most of traditional Access Control Based on Certificate (ACBC) will generate abundant certificate, which will lend to the Meta-Data Server (MDS) overload. So we introduce Identity-Based Encryption (IBE) to the OBSS, and proposed a novel Access Control Based on IBE (ACBI). In ACBI the public key can be calculated according with their identity, and need not maintain public key certificate for each entity. Thereby ACBI can significantly reduce the overhead of certificate management. At the same time, ACBI associated the access control list (ACL) with the object, the users will not required to ask the MDS for authorization, they can directly access the storage device. The storage system depends on user´s identity to authenticate user´s access permission, which simplifying the access control process. The experiment results demonstrated that security overhead of ACBI on MDS is only 48.7% in comparison to ACBC. Meanwhile, ACBI made the security module load of OBSS only employ 74.5% response time compared to ACBC.
Keywords :
authorisation; distributed processing; public key cryptography; storage management; certificate based access control; certificate management; distributed storage architecture; identity-based encryption; large-scale storage systems; meta-data server; object-based storage system access control; public key certificate; storage security; Access control; Computer security; Data security; Identity-based encryption; Information security; Information technology; National security; Permission; Public key; Secure storage; access control; identity-based encryption; object-based storage system;
Conference_Titel :
Intelligent Information Technology and Security Informatics (IITSI), 2010 Third International Symposium on
Conference_Location :
Jinggangshan
Print_ISBN :
978-1-4244-6730-3
Electronic_ISBN :
978-1-4244-6743-3
DOI :
10.1109/IITSI.2010.53