• DocumentCode
    2195956
  • Title

    A Secure Storage System Combining Secret Sharing Schemes and Byzantine Quorum Mechanisms

  • Author

    Wang, Qiongxiao ; Jing, Jiwu ; Lin, Jingqiang

  • Author_Institution
    State Key Lab. of Inf. Security, Grad. Univ. of Chinese Acad. of Sci., Beijing, China
  • fYear
    2010
  • fDate
    June 29 2010-July 1 2010
  • Firstpage
    596
  • Lastpage
    603
  • Abstract
    By combining Byzantine quorum systems (BQS) and secret sharing schemes, this paper presents a secure storage system, S2-BQS, tolerating servers´ Byzantine failures. S2-BQS provides information-theoretic security for the stored sensitive data inherited from perfect secret sharing schemes (PSS). Compared to traditional realizations of BQS in storage systems, S2-BQS doesn´t replicate data in servers directly. Instead, secret shares obtained from PSS are stored in different servers. To retrieve the correct data from S2-BQS, we design a new verification method for PSS without using any extra information or extra algorithms except reconstructing the secret for several times using PSS. Due to the simplicity of S2-BQS´s structure and protocols, the computation and communication overhead on servers are low, making it almost impossible to launch resource-clogging denial-of-service attacks to servers in S2-BQS. We also propose a specialized S2-BQS called S3-BQS in which Shamir´s secret sharing scheme is employed. It shows that our approach is flexible and easy to be realized. The system evaluation shows that an S3-BQS with optimized protocols has better computation performance.
  • Keywords
    distributed memory systems; fault tolerant computing; formal verification; security of data; storage management; Byzantine failure; Byzantine fault tolerance; Byzantine quorum system; communication overhead; computation overhead; distributed storage system; information-theoretic security; optimized protocol; perfect secret sharing scheme; resource-clogging denial-of-service attack; secure storage system; stored sensitive data; system evaluation; verification method; Availability; Buildings; Cryptography; Protocols; Secure storage; Servers; Byzantine fault tolerance; Byzantine quorum systems; Secret sharing schemes;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer and Information Technology (CIT), 2010 IEEE 10th International Conference on
  • Conference_Location
    Bradford
  • Print_ISBN
    978-1-4244-7547-6
  • Type

    conf

  • DOI
    10.1109/CIT.2010.123
  • Filename
    5578120