Towards a Trusted Hadoop Storage Platform: Design Considerations of an AES Based Encryption Scheme with TPM Rooted Key Protections

被引:4
|
作者
Cohen, Jason [1 ]
Acharya, Subatra [2 ]
机构
[1] Towson Univ, Hewlett Packard Co, Towson, MD 21252 USA
[2] Towson Univ, Dept Informat & Comp Sci, Towson, MD 21252 USA
关键词
Hadoop; HDFS; Trusted Computing; Encryption; AES-NI;
D O I
10.1109/UIC-ATC.2013.57
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper will examine the concept of combining trusted computing technologies with the Apache Hadoop Distributed File System (HDFS) in an effort to address concerns of data confidentiality and integrity. We discuss a motivation and address a set of common security concerns within HDFS through infrastructure and software involving data-at-rest encryption and integrity validation. To accomplish these goals, we make use of technology from the Trusted Computing Group (TCG), such as the pervasively available Trusted Platform Module (TPM). In addition, we discuss our design considerations in building an encryption framework for Hadoop in a trustworthy manner, and results of our experiments creating an encryption scheme for Hadoop utilizing hardware key protections and AES-NI for encryption acceleration. As part of this design we examine the recently implemented crypto framework for Hadoop and independently test the performance claims of AES-NI to mitigate performance overhead.
引用
收藏
页码:444 / 451
页数:8
相关论文
共 4 条
  • [1] Towards a trusted HDFS storage platform: Mitigating threats to Hadoop infrastructures using hardware-accelerated encryption with TPM-rooted key protection
    Cohen, Jason C.
    Acharya, Subrata
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2014, 19 (03) : 224 - 244
  • [2] Efficient ID-based TPM key loading scheme for trusted platform
    Song C.
    Liu B.
    Hu Z.-M.
    Xin Y.
    Yang Y.-X.
    Yin H.
    Journal of China Universities of Posts and Telecommunications, 2010, 17 (04): : 74 - 79
  • [4] TOWARDS DATA STORAGE SCHEME IN BLOCKCHAIN BASED SERVERLESS ENVIRONMENT: AES ENCRYPTION AND DECRYPTION ALGORITHM APPROACH
    Kandpal, Meenakshi
    Pritwani, Yash
    Misra, Chinmaya
    Yadav, Amrendra Singh
    Barik, Rabindra Kumar
    FACTA UNIVERSITATIS-SERIES ELECTRONICS AND ENERGETICS, 2024, 37 (02) : 317 - 342