Kurma: Secure Geo-Distributed Multi-Cloud Storage Gateways

被引:3
作者
Chen, Ming [1 ]
Zadok, Erez [1 ]
机构
[1] SUNY Stony Brook, Stony Brook, NY 11794 USA
来源
SYSTOR '19: PROCEEDINGS OF THE 12TH ACM INTERNATIONAL SYSTEMS AND STORAGE CONFERENCE | 2019年
关键词
Multi-cloud; cloud storage gateways; storage security; FILE-SYSTEM;
D O I
10.1145/3319647.3325830
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Cloud storage is highly available, scalable, and cost-efficient. Yet, many cannot store data in cloud due to security concerns and legacy infrastructure such as network-attached storage ( NAS). We describe Kurma, a cloud storage gateway system that allows NAS-based programs to seamlessly and securely access cloud storage. To share files among distant clients, Kurma maintains a unified file-system namespace by replicating metadata across geo-distributed gateways. Kurma stores only encrypted data blocks in clouds, keeps file-system and security metadata on-premises, and can verify data integrity and freshness without any trusted third party. Kurma uses multiple clouds to prevent cloud outage and vendor lock-in. Kurma's performance is 52-91% that of a local NFS server while providing geo-replication, confidentiality, integrity, and high availability.
引用
收藏
页码:109 / 120
页数:12
相关论文
共 59 条
[1]   A survey on data security issues in cloud computing: From single to multi-clouds [J].
Alzain, Mohammed A. ;
Soh, Ben ;
Pardede, Eric .
Journal of Software, 2013, 8 (05) :1068-1078
[2]  
[Anonymous], 2010, Proc. of the 1st ACM Symposium on Cloud Computing. SoCC'10
[3]  
[Anonymous], 2008, P USENIX ANN TECHN C
[4]  
[Anonymous], 2008, JERASURE LIB C C FAC
[5]  
[Anonymous], 2011, P 6 WORKSHOP MIDDLEW, DOI DOI 10.1145/2093185.2093186
[6]   A View of Cloud Computing [J].
Armbrust, Michael ;
Fox, Armando ;
Griffith, Rean ;
Joseph, Anthony D. ;
Katz, Randy ;
Konwinski, Andy ;
Lee, Gunho ;
Patterson, David ;
Rabkin, Ariel ;
Stoica, Ion ;
Zaharia, Matei .
COMMUNICATIONS OF THE ACM, 2010, 53 (04) :50-58
[7]   Eventual Consistency Today: Limitations, Extensions, and Beyond [J].
Bailis, Peter ;
Ghodsi, Ali .
COMMUNICATIONS OF THE ACM, 2013, 56 (05) :55-63
[8]  
Bermbach D., 2011, Proceedings of the 2011 IEEE 4th International Conference on Cloud Computing (CLOUD 2011), P452, DOI 10.1109/CLOUD.2011.62
[9]  
Bessani A., 2014, USENIX ATC 14, P169
[10]   DEPSKY: Dependable and Secure Storage in a Cloud-of-Clouds [J].
Bessani, Alysson ;
Correia, Miguel ;
Quaresma, Bruno ;
Andre, Fernando ;
Sousa, Paulo .
ACM TRANSACTIONS ON STORAGE, 2013, 9 (04)