DocumentCode :
1994139
Title :
Characterizing throughput bottlenecks for secure GridFTP transfers
Author :
Vardoyan, G. ; Kettimuthu, Rajkumar ; Link, M. ; Tuecke, Steven
Author_Institution :
Comput. Inst., Univ. of Chicago, Chicago, IL, USA
fYear :
2013
fDate :
28-31 Jan. 2013
Firstpage :
861
Lastpage :
866
Abstract :
GridFTP is the de facto standard for bulk data movement in distributed science environments. It extends the legacy FTP to provide strong security, reliability, and high performance. GridFTP, like FTP, is a two-channel protocol-the control channel is used for sending commands and responses, and the data channel is used for transferring the actual data. The control channel is encrypted and integrity protected by default. The data channel is authenticated by default. Encryption and integrity protection are both supported on the data channel but are not enabled by default because of their high CPU cost and low data transfer rates. In this paper, we present an extensive experimental study on the performance implications of enabling integrity protection and encryption on the data channel. We show that in a vast number of cases involving the use of nonthreaded Globus GridFTP servers on multicore systems, throughputs of secure transfers are not comparable to those of nonencrypted and nonintegrity-protected transfers because of an inefficient use of available processors. However, in cases where a strong desire for higher security levels permits larger expenditures in processing, integrity protection and sometimes even crypto-graphic confidentiality can be provided without having to suffer a decline in throughput. We show that this can be accomplished through threaded Globus GridFTP server instances configured with appropriately chosen parallelism and concurrency, allowing for a more effective use of available system resources.
Keywords :
cryptographic protocols; data privacy; multiprocessing systems; telecommunication channels; telecommunication network reliability; CPU; GridFTP transfer security; bulk data movement; cryptographic confidentiality; data control channel; data transfer; distributed science environment; encryption; integrity protection; multicore system; nonencrypted-protected transfer; nonintegrity-protected transfer; nonthreaded Globus GridFTP server; reliability; two-channel protocol; Concurrent computing; Cryptography; Data transfer; Instruction sets; Local area networks; Parallel processing; Throughput;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computing, Networking and Communications (ICNC), 2013 International Conference on
Conference_Location :
San Diego, CA
Print_ISBN :
978-1-4673-5287-1
Electronic_ISBN :
978-1-4673-5286-4
Type :
conf
DOI :
10.1109/ICCNC.2013.6504202
Filename :
6504202
Link To Document :
بازگشت