DocumentCode
3269990
Title
A Credential-based Security Mechanism for Object-based Storage
Author
Li, Zhongmin ; Yu, Zhanwu
Author_Institution
State Key Lab. of Inf. Eng. in Surveying, Mapping & Remote Sensing, Wuhan Univ.
Volume
3
fYear
2006
fDate
25-28 June 2006
Firstpage
1610
Lastpage
1614
Abstract
Unlike direct attached storage (DAS), network attached storage (NAS) or storage area network (SAN), object-based storage, an emerging network storage technology, separates the control path, the data path and the management path, and enables direct interaction between clients and the storage devices. Clients acquire only the metadata information and some cryptographic primitives from the metadata servers. The clients, the metadata servers and the storage devices are separate, so it is very important to construct a security mechanism for securing data exchange between them. In this paper we present a credential-based security mechanism for object-based storage that stands on existing security infrastructure. In this mechanism, the object-based storage device (OSD) security model is a credential-based access control system, and commands transfer and data access both need be authorized. The client requests a credential including a capability key from the security manager after authenticated by the security manager through a PKI system. The security manager and the OSD device (OBSD) have a shared secret key to calculate the capability key which is used as a single secret key to identify the integrity of credential and encrypt the communications between the client and the OBSD
Keywords
client-server systems; message authentication; meta data; public key cryptography; storage management; telecommunication security; OSD device; PKI system; access control system; authentication; clients; credential-based security; cryptographic primitives; data exchange; encryption; metadata servers; object-based storage device; Access control; Communication system security; Computer architecture; Data security; Information security; Laboratories; Network servers; Secure storage; Storage area networks; Switches;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications, Circuits and Systems Proceedings, 2006 International Conference on
Conference_Location
Guilin
Print_ISBN
0-7803-9584-0
Electronic_ISBN
0-7803-9585-9
Type
conf
DOI
10.1109/ICCCAS.2006.284981
Filename
4064207
Link To Document