• DocumentCode
    2876209
  • Title

    Design and Implementation of Self-securing Disk

  • Author

    Zeng, Mengqi ; Gu, Dawu ; Hou, Fangyong ; Zhang, Yuanyuan ; Cheng, Tao

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Shanghai Jiao Tong Univ., Shanghai, China
  • fYear
    2009
  • fDate
    9-11 July 2009
  • Firstpage
    405
  • Lastpage
    412
  • Abstract
    Self-securing storage devices prevents intruders from undetectably tampering with or permanently deleting stored data. To accomplish this, we design an efficient self-securing disk architecture, which is based on traditional self-securing storage prototype S4: 1) On the confidentiality protection side, authenticated encryption mode GCM is adapted to process disk block in parallel ,and authentication latency is overlapped with disk access latency so that our scheme is more efficient and secure than Windows BitLocker. 2) On the integrity protection side, GHASH proposed in GCM is used to generate MAC which is more efficient than SHA-1, MD5. Moreover, ldquoMinimum Integrity Verification Treerdquo is put forward to decrease performance loss at a maximum. 3) On the access control protection side, we propose a cryptographically featured capability based access control model, which is based on existing OSD access control model. We use hybrid hard drive as an instance to build a self-securing disk prototype which is implemented by simulation. The encryption/authentication overheads are significantly reduced due to buffer techniques and combined GCM/Flash scheme. According to the simulation results, the performance overhead is less than 18%, which is efficient and practical.
  • Keywords
    authorisation; cryptography; disc drives; hard discs; message authentication; access control model; authenticated encryption mode; authentication latency; disk access latency; hybrid hard drive; minimum integrity verification tree; self-securing disk architecture; self-securing disk prototype; self-securing storage device; Access control; Authentication; Cryptography; Delay; Drives; Performance loss; Protection; Prototypes; Secure storage; Virtual prototyping; Access Control; Encryption; Integrity; Self-securing Disk;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Networking, Architecture, and Storage, 2009. NAS 2009. IEEE International Conference on
  • Conference_Location
    Hunan
  • Print_ISBN
    978-0-7695-3741-2
  • Type

    conf

  • DOI
    10.1109/NAS.2009.70
  • Filename
    5197357