Efficient security interface for high-performance Ceph storage systems

被引:0
|
作者
Parast, Fatemeh Khoda [1 ]
Damghani, Seyed Alireza [1 ]
Kelly, Brett [2 ]
Wang, Yang [3 ]
Kent, Kenneth B. [1 ]
机构
[1] Univ New Brunswick, Fac Comp Sci, Fredericton, NB, Canada
[2] 45 Drives Inc, Sydney, NS, Canada
[3] Chinese Acad Sci, Shenzhen Inst Adv Technol, Shenzhen, Peoples R China
基金
加拿大自然科学与工程研究理事会;
关键词
Security; Storage; High-performance computing; Ceph; Cryptography; CLOUD;
D O I
10.1016/j.future.2024.107571
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Ceph portrays a resilient clustered storage solution with supporting object, block, and file storage capabilities with no single point of failure. Despite these qualifications, data confidentiality defines a concern in the system, as authentication and access control are the only data protection security services in Ceph. CephArmor was proposed as a third-party security interface to protect data confidentiality by adding an extra protection layer to data at rest. Despite the added layer, the initial design of the API needed to be more efficient in addressing security and performance simultaneously. In this study, we propose a new architectural design to address the associated issues with the preliminary prototype. Comprehensive performance and security analysis verify the improvement of the proposed method compared to the initial approach. The benchmark result has indicated a 37% improvement on average in IOPS, elapsed time, and bandwidth for the write benchmark compared to the initial model.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] CephArmor: A Lightweight Cryptographic Interface for Secure High-Performance Ceph Storage Systems
    Khoda Parast, Fatemeh
    Kelly, Brett
    Hakak, Saqib
    Wang, Yang
    Kent, Kenneth B.
    IEEE ACCESS, 2022, 10 : 127911 - 127927
  • [2] Efficient journaling writeback schemes for reliable and high-performance storage systems
    Seung-Ho Lim
    Hyun Jin Choi
    Doo-Soon Park
    Personal and Ubiquitous Computing, 2013, 17 : 1761 - 1774
  • [3] Efficient journaling writeback schemes for reliable and high-performance storage systems
    Lim, Seung-Ho
    Choi, Hyun Jin
    Park, Doo-Soon
    PERSONAL AND UBIQUITOUS COMPUTING, 2013, 17 (08) : 1761 - 1774
  • [4] Ceph: A scalable, high-performance distributed file system
    Weil, Sage A.
    Brandt, Scott A.
    Miller, Ethan L.
    Long, Darrell D. E.
    Maltzahn, Carlos
    USENIX ASSOCIATION 7TH USENIX SYMPOSIUM ON OPERATING SYSTEMS DESIGN AND IMPLEMENTATION, 2006, : 307 - +
  • [7] Energy-efficient high-performance storage system
    Wang, Jun
    2008 IEEE INTERNATIONAL SYMPOSIUM ON PARALLEL & DISTRIBUTED PROCESSING, VOLS 1-8, 2008, : 2640 - 2644
  • [8] MRA - A COMPUTATIONAL TECHNIQUE FOR SECURITY IN HIGH-PERFORMANCE SYSTEMS
    ABDELGUERFI, M
    DUNHAM, A
    PATTERSON, W
    COMPUTER SECURITY, 1993, 37 : 401 - 417
  • [9] Quota enforcement for high-performance distributed storage systems
    Pollack, Kristal T.
    Long, Darrell D. E.
    Golding, Richard A.
    Becker-Szendy, Ralph A.
    Reed, Benjamin
    24TH IEEE CONFERENCE ON MASS STORAGE SYSTEMS AND TECHNOLOGIES, PROCEEDINGS, 2007, : 72 - +
  • [10] Configurable computing for high-security/high-performance ambient systems
    Gogniat, G
    Burleson, W
    Bossuet, L
    EMBEDDED COMPUTER SYSTEMS: ARCHITECTURES, MODELING, AND SIMULATION, 2005, 3553 : 72 - 81