DocumentCode :
3269990
Title :
A Credential-based Security Mechanism for Object-based Storage
Author :
Li, Zhongmin ; Yu, Zhanwu
Author_Institution :
State Key Lab. of Inf. Eng. in Surveying, Mapping & Remote Sensing, Wuhan Univ.
Volume :
3
fYear :
2006
fDate :
25-28 June 2006
Firstpage :
1610
Lastpage :
1614
Abstract :
Unlike direct attached storage (DAS), network attached storage (NAS) or storage area network (SAN), object-based storage, an emerging network storage technology, separates the control path, the data path and the management path, and enables direct interaction between clients and the storage devices. Clients acquire only the metadata information and some cryptographic primitives from the metadata servers. The clients, the metadata servers and the storage devices are separate, so it is very important to construct a security mechanism for securing data exchange between them. In this paper we present a credential-based security mechanism for object-based storage that stands on existing security infrastructure. In this mechanism, the object-based storage device (OSD) security model is a credential-based access control system, and commands transfer and data access both need be authorized. The client requests a credential including a capability key from the security manager after authenticated by the security manager through a PKI system. The security manager and the OSD device (OBSD) have a shared secret key to calculate the capability key which is used as a single secret key to identify the integrity of credential and encrypt the communications between the client and the OBSD
Keywords :
client-server systems; message authentication; meta data; public key cryptography; storage management; telecommunication security; OSD device; PKI system; access control system; authentication; clients; credential-based security; cryptographic primitives; data exchange; encryption; metadata servers; object-based storage device; Access control; Communication system security; Computer architecture; Data security; Information security; Laboratories; Network servers; Secure storage; Storage area networks; Switches;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications, Circuits and Systems Proceedings, 2006 International Conference on
Conference_Location :
Guilin
Print_ISBN :
0-7803-9584-0
Electronic_ISBN :
0-7803-9585-9
Type :
conf
DOI :
10.1109/ICCCAS.2006.284981
Filename :
4064207
Link To Document :
بازگشت