Employing Object-Based Storage Devices to Embed File Access Control in Storage
نویسندگان
چکیده
This paper presents a proposal to em bed the file access control into object-based storage devices (OSD) to achieve powerf ul storage security with rich semantics; and two application pr ototypes, the OSD-based intrusion detection ( ID) and the f iner-grained (than the f ile-level) acce ss control, are im plemented to show its feasibility. To embed file access control into st orage, one of vital challenges is how to connect a file with its corresponding storage units and its access control rule. In this design, OSD itself can com plete the connec tion—for I D, the one ( file) to one ( object) relationship is used to link f iles and thei r storage objects/access rules together by the storage. As the r elationship is extended to one to m ore, one file can be divided into several objects in accordance with its access cont rol semantics; then assigning users with different access permissions based on the f ile’s internal structure (which is the m eaning of the finer-grained access control) is feasible. In addition, the OSD standard is discussed to extend to define new object attributes f or file access control. Both prototypes are built based on the OSD r eference implementation provided by Intel. Testing results show that the extra overheads introduced by this design are acceptable.
منابع مشابه
Improving Data Grids Performance by Using Modified Dynamic Hierarchical Replication Strategy
Abstract: A Data Grid connects a collection of geographically distributed computational and storage resources that enables users to share data and other resources. Data replication, a technique much discussed by Data Grid researchers in recent years creates multiple copies of file and places them in various locations to shorten file access times. In this paper, a dynamic data replication strate...
متن کاملAn Efficient Data Replication Strategy in Large-Scale Data Grid Environments Based on Availability and Popularity
The data grid technology, which uses the scale of the Internet to solve storage limitation for the huge amount of data, has become one of the hot research topics. Recently, data replication strategies have been widely employed in distributed environment to copy frequently accessed data in suitable sites. The primary purposes are shortening distance of file transmission and achieving files from ...
متن کاملTowards Mass Storage Systems with Object Granularity
Many applications, that need mass storage, manipulate data sets with KB – MB size objects. In contrast, mass storage devices work most efficiently for the storage and transfer of large files in the MB – GB range. Reflecting these device characteristics, mass storage systems typically have a file level granularity. To overcome the impedance mismatch between small objects and large files, we prop...
متن کاملSecurity for a High Performance Commodity Storage Subsystem
How do we incorporate security into a high performance commodity storage subsystem? Technology trends and the increasing importance of I/O bound workloads are driving the development of commodity network attached storage devices which deliver both increased functionality and increased performance to end-users. In the network attached world, storage devices co-exist on the network with their cli...
متن کاملAdaptive Replica Management for Large-scale Object-based Storage Devices
Replica management is basic and challenging issue for distributed storage system designer. The objective of this paper is to dynamically create, migrate and delete replicas among nodes in response to changes in the access patterns. This paper presents an Adaptive Replica Management Model for large-scale Object-based Storage Devices (OSDs). The model expresses availability and consistency mainte...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- Intelligent Automation & Soft Computing
دوره 17 شماره
صفحات -
تاریخ انتشار 2011