A credential-based security mechanism for object storage

被引:0
|
作者
Li, Zhongmin [1 ]
Yu, Zhanwu [1 ]
机构
[1] Wuhan Univ, State Key Lab Informat Engn Surveying Mapping & R, Wuhan 430079, Hubei, Peoples R China
来源
2006 INTERNATIONAL CONFERENCE ON COMMUNICATIONS, CIRCUITS AND SYSTEMS PROCEEDINGS, VOLS 1-4: VOL 1: SIGNAL PROCESSING | 2006年
关键词
D O I
10.1109/ICCCAS.2006.284981
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Unlike Direct Attached Storage (DAS), Network Attached Storage (NAS) or Storage Area Network (SAN), Object-based Storage, an emerging, network storage technology, separates the control path, the data path and the management path, and enables direct interaction between clients and the storage devices. Clients acquire only the metadata information and some cryptographic primitives from the metadata servers. The Clients., the metadata servers and the storage devices are separate, so it is very important to construct a security mechanism for securing data exchange between them. In this paper we present a credential-based security mechanism for Object-based Storage that stands on existing security infrastructure. In this mechanism, the Object-based Storage Device (OSD) security model is a credential-based access control system, and commands transfer and data access both need be authorized. The Client requests a credential including a capability key from the Security Manager after authenticated by the Security Manager through a PKI system. The Security Manager and the OSD Device (OBSD) have a shared secret key to calculate the capability key which is used as a single secret key to identify the integrity of credential and encrypt the communications between the Client and the OBSD.
引用
收藏
页码:1610 / +
页数:2
相关论文
共 50 条
  • [31] A security model for anonymous credential systems
    Pashalidis, A
    Mitchell, CJ
    INFORMATION SECURITY MANAGEMENT, EDUCATION AND PRIVACY, 2004, 148 : 183 - 199
  • [32] A Combined Optimized WLAN Communication Security Algorithm Based on Distributed Object Storage
    Pu, Zaiyi
    BASIC & CLINICAL PHARMACOLOGY & TOXICOLOGY, 2019, 124 : 291 - 292
  • [33] OIDM: An intrusion detection mechanism for object-based storage system
    Wang, Zhilcun
    Feng, Dan
    Zeng, Lingfang
    Tian, Lei
    2006 INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY, PTS 1 AND 2, PROCEEDINGS, 2006, : 617 - 620
  • [34] Design and implementation of a security framework based on the object-based storage-device standard
    Ko, Kwangsun
    Kim, Gu Su
    Kim, June
    Han, JungHyun
    Kim, Ungmo
    Eom, Young Ik
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2006, PT 1, 2006, 3980 : 1028 - 1035
  • [35] Data Security Storage and Verification Mechanism Based on Distributed Ledger Technology
    Chen, Lin
    Shangguan, Jun
    Applied Mathematics and Nonlinear Sciences, 2024, 9 (01)
  • [36] Data security storage mechanism based on blockchain industrial Internet of Things
    Wang, Jin
    Chen, Jiahao
    Ren, Yongjun
    Sharma, Pradip Kumar
    Alfarraj, Osama
    Tolba, Amr
    COMPUTERS & INDUSTRIAL ENGINEERING, 2022, 164
  • [37] An Enhanced Erasure Code-Based Security Mechanism for Cloud Storage
    Wang, Wenfeng
    Li, Peiwu
    Han, Longzhe
    Huang, Shuqiang
    Xu, Kefu
    Yu, Changgui
    Lei, Jin'e
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2014, 2014
  • [38] Do Not Trust the Clouds Easily: The Insecurity of Content Security Policy Based on Object Storage
    Lv, Yangzixing
    Shi, Wei
    Zhang, Weiyong
    Lu, Hui
    Tian, Zhihong
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (12) : 10462 - 10470
  • [39] Credential and Security Issues of Cloud Service Models
    Dewangan, Bhupesh Kumar
    Agarwal, Amit
    Venkatadri
    Pasricha, Ashutosh
    PROCEEDINGS ON 2016 2ND INTERNATIONAL CONFERENCE ON NEXT GENERATION COMPUTING TECHNOLOGIES (NGCT), 2016, : 888 - 892
  • [40] Security analysis and fix of an anonymous credential system
    Yang, YJ
    Bao, F
    Deng, RH
    INFORMATION SECURITY AND PRIVACY, PROCEEDINGS, 2005, 3574 : 537 - 547