DocumentCode
3115666
Title
Towards a Trusted Hadoop Storage Platform: Design Considerations of an AES Based Encryption Scheme with TPM Rooted Key Protections
Author
Cohen, Johanne ; Acharya, Sanjeev
Author_Institution
Dept. of Comput. & Inf. Sci., Towson Univ./Hewlett Packard Co., Towson, MD, USA
fYear
2013
fDate
18-21 Dec. 2013
Firstpage
444
Lastpage
451
Abstract
This paper will examine the concept of combining trusted computing technologies with the Apache Hadoop Distributed File System (HDFS) in an effort to address concerns of data confidentiality and integrity. We discuss a motivation and address a set of common security concerns within HDFS through infrastructure and software involving data-at-rest encryption and integrity validation. To accomplish these goals, we make use of technology from the Trusted Computing Group (TCG), such as the pervasively available Trusted Platform Module (TPM). In addition, we discuss our design considerations in building an encryption framework for Hadoop in a trustworthy manner, and results of our experiments creating an encryption scheme for Hadoop utilizing hardware key protections and AES-NI for encryption acceleration. As part of this design we examine the recently implemented crypto framework for Hadoop and independently test the performance claims of AES-NI to mitigate performance overhead.
Keywords
cryptography; data integrity; storage management; trusted computing; AES based encryption; AES-NI; Apache Hadoop distributed file system; HDFS; TCG; TPM rooted key protections; crypto framework; data confidentiality; data integrity validation; data-at-rest encryption; encryption acceleration; encryption framework; hardware key protections; trusted Hadoop storage platform; trusted computing group; trusted computing technologies; trusted platform module; Encryption; Java; Nickel; Software; Throughput; AES-NI; Encryption; HDFS; Hadoop; Trusted Computing;
fLanguage
English
Publisher
ieee
Conference_Titel
Ubiquitous Intelligence and Computing, 2013 IEEE 10th International Conference on and 10th International Conference on Autonomic and Trusted Computing (UIC/ATC)
Conference_Location
Vietri sul Mere
Print_ISBN
978-1-4799-2481-3
Type
conf
DOI
10.1109/UIC-ATC.2013.57
Filename
6726242
Link To Document