• DocumentCode
    3115666
  • Title

    Towards a Trusted Hadoop Storage Platform: Design Considerations of an AES Based Encryption Scheme with TPM Rooted Key Protections

  • Author

    Cohen, Johanne ; Acharya, Sanjeev

  • Author_Institution
    Dept. of Comput. & Inf. Sci., Towson Univ./Hewlett Packard Co., Towson, MD, USA
  • fYear
    2013
  • fDate
    18-21 Dec. 2013
  • Firstpage
    444
  • Lastpage
    451
  • Abstract
    This paper will examine the concept of combining trusted computing technologies with the Apache Hadoop Distributed File System (HDFS) in an effort to address concerns of data confidentiality and integrity. We discuss a motivation and address a set of common security concerns within HDFS through infrastructure and software involving data-at-rest encryption and integrity validation. To accomplish these goals, we make use of technology from the Trusted Computing Group (TCG), such as the pervasively available Trusted Platform Module (TPM). In addition, we discuss our design considerations in building an encryption framework for Hadoop in a trustworthy manner, and results of our experiments creating an encryption scheme for Hadoop utilizing hardware key protections and AES-NI for encryption acceleration. As part of this design we examine the recently implemented crypto framework for Hadoop and independently test the performance claims of AES-NI to mitigate performance overhead.
  • Keywords
    cryptography; data integrity; storage management; trusted computing; AES based encryption; AES-NI; Apache Hadoop distributed file system; HDFS; TCG; TPM rooted key protections; crypto framework; data confidentiality; data integrity validation; data-at-rest encryption; encryption acceleration; encryption framework; hardware key protections; trusted Hadoop storage platform; trusted computing group; trusted computing technologies; trusted platform module; Encryption; Java; Nickel; Software; Throughput; AES-NI; Encryption; HDFS; Hadoop; Trusted Computing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Ubiquitous Intelligence and Computing, 2013 IEEE 10th International Conference on and 10th International Conference on Autonomic and Trusted Computing (UIC/ATC)
  • Conference_Location
    Vietri sul Mere
  • Print_ISBN
    978-1-4799-2481-3
  • Type

    conf

  • DOI
    10.1109/UIC-ATC.2013.57
  • Filename
    6726242