This paper will examine the concept of combining trusted computing technologies with the Apache Hadoop Distributed File System (HDFS) in an effort to address concerns of data confidentiality and integrity. We discuss a motivation and address a set of common security concerns within HDFS through infrastructure and software involving data-at-rest encryption and integrity validation. To accomplish these goals, we make use of technology from the Trusted Computing Group (TCG), such as the pervasively available Trusted Platform Module (TPM). In addition, we discuss our design considerations in building an encryption framework for Hadoop in a trustworthy manner, and results of our experiments creating an encryption scheme for Hadoop utilizing hardware key protections and AES-NI for encryption acceleration. As part of this design we examine the recently implemented crypto framework for Hadoop and independently test the performance claims of AES-NI to mitigate performance overhead.
机构:
Information Security Center, State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications
Key Laboratory of Network and Information Attack and Defense Technology of Ministry of Education, Beijing University of Posts and Telecommunications
National Engineering Laboratory for Disaster Backup and Recovery, Beijing University of Posts and Telecommunications
Beijing Safe-Code Technology Co. Ltd.Information Security Center, State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications
Song C.
Liu B.
论文数: 0引用数: 0
h-index: 0
机构:
Information Security Center, State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications
Key Laboratory of Network and Information Attack and Defense Technology of Ministry of Education, Beijing University of Posts and Telecommunications
National Engineering Laboratory for Disaster Backup and Recovery, Beijing University of Posts and Telecommunications
Beijing Safe-Code Technology Co. Ltd.Information Security Center, State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications
Liu B.
Hu Z.-M.
论文数: 0引用数: 0
h-index: 0
机构:
Information Security Center, State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications
Key Laboratory of Network and Information Attack and Defense Technology of Ministry of Education, Beijing University of Posts and Telecommunications
National Engineering Laboratory for Disaster Backup and Recovery, Beijing University of Posts and TelecommunicationsInformation Security Center, State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications
Hu Z.-M.
Xin Y.
论文数: 0引用数: 0
h-index: 0
机构:
Information Security Center, State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications
Key Laboratory of Network and Information Attack and Defense Technology of Ministry of Education, Beijing University of Posts and Telecommunications
National Engineering Laboratory for Disaster Backup and Recovery, Beijing University of Posts and Telecommunications
Beijing Safe-Code Technology Co. Ltd.Information Security Center, State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications
Xin Y.
Yang Y.-X.
论文数: 0引用数: 0
h-index: 0
机构:
Information Security Center, State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications
Key Laboratory of Network and Information Attack and Defense Technology of Ministry of Education, Beijing University of Posts and Telecommunications
National Engineering Laboratory for Disaster Backup and Recovery, Beijing University of Posts and TelecommunicationsInformation Security Center, State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications
Yang Y.-X.
Yin H.
论文数: 0引用数: 0
h-index: 0
机构:
Huawei Technology LtdInformation Security Center, State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications
Yin H.
Journal of China Universities of Posts and Telecommunications,
2010,
17
(04):
: 74
-
79