• DocumentCode
    3633338
  • Title

    VAOFS: A Verifiable Append-Only File System for Regulatory Compliance

  • Author

    Da Xiao;Wenbin Yao;Chunhua Wu;Cong Wang;Yixian Yang

  • Author_Institution
    Nat. Eng. Lab. for Disaster Backup & Recovery, Beijing Univ. of Posts & Telecommun., Beijing, China
  • fYear
    2009
  • Firstpage
    325
  • Lastpage
    330
  • Abstract
    Append-only file systems, with which data can only be updated in an append-only manner, are of great importance to the regulatory compliance requirements for storing immutable data. However, existing approaches fail to provide the verifiability of the append-only property of the file system in the presence of an inside attacker who can manipulate on-disk data directly, and thus are unsuitable for use in regulatory compliance. This paper presents the design and implementation of VAOFS, a Verifiable Append-Only File System for regulatory compliance. Verifiability is provided by a tamper resistant hardware device cooperating with an instrumented file system. Non-appending operations can be detected in an audit process. A time-based secure deletion method is also proposed to handle file deletion in VAOFS. Experiments with a prototype VAOFS called ext3ao built with ext3 show that the overhead of ext3ao is 53.0% compared with ext3; the audit process is efficient.
  • Keywords
    "File systems","Hardware","Prototypes","Instruments","Data security","Image storage","Postal services","Grid computing","Telecommunication computing","Data engineering"
  • Publisher
    ieee
  • Conference_Titel
    Grid and Cooperative Computing, 2009. GCC ´09. Eighth International Conference on
  • Print_ISBN
    978-0-7695-3766-5
  • Type

    conf

  • DOI
    10.1109/GCC.2009.52
  • Filename
    5279563