Proceedings Article10.1109/MSST.2010.5496979
Disk-enabled authenticated encryption
Kevin R. B. Butler,Stephen McLaughlin,Patrick McDaniel +2 more
- 03 May 2010
- pp 1-6
TL;DR: These experiments show that proper tuning of system parameters can eliminate many of the costs associated with managing security metadata, with less than a 2% decrease in IOPS versus regular disks.
read more
Abstract: Storage is increasingly becoming a vector for data compromise. Solutions for protecting on-disk data confidentiality and integrity to date have been limited in their effectiveness. Providing authenticated encryption, or simultaneous encryption with integrity information, is important to protect data at rest. In this paper, we propose that disks augmented with non-volatile storage (e.g., hybrid hard disks) and cryptographic processors (e.g., FDE drives) may provide a solution for authenticated encryption, storing security metadata within the drive itself to eliminate dependences on other parts of the system. We augment the DiskSim simulator with a flash simulator to evaluate the costs associated with managing operational overheads. These experiments show that proper tuning of system parameters can eliminate many of the costs associated with managing security metadata, with less than a 2% decrease in IOPS versus regular disks.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Patent
Self-encrypting flash drive
Ashwin Kamath,Paul E. Prince,Trevor Smith +2 more
- 27 Feb 2014
TL;DR: In this paper, the authors propose a method to encrypt a plaintext message, encrypting the plaintext messages and generating a cipher text and authentication data, storing the cipher text in a user data portion of a data storage device, and storing the authentication data in a meta data portion.
6
Secure storage - Confidentiality and authentication
TL;DR: In this article , the authors present a comprehensive study of full disk encryption solutions and compare their features from a security perspective, and additionally present threat models for authenticated disk encryption and present a systematized analysis of the techniques usable in these settings.
2
Patent
Method and apparatus for performing a integrity check
Lu Xiao,Suresh Bollapragada +1 more
- 24 Mar 2016
TL;DR: Disclosed as discussed by the authors is a method for performing a message integrity check, in which a processor reads a message from a storage device and determines one or more second level sections from the plurality of first level sections.
1
References
•Proceedings Article
Space-Efficient Block Storage Integrity.
Alina Oprea,Michael K. Reiter +1 more
- 01 Jan 2005
TL;DR: A scheme that provably implements basic block integrity, that exhibits a tradeoff between the level of security and the additional client’s storage overhead, and that in empirical evaluations requires an average of only 0.01 bytes per 1024-byte block is demonstrated.
98
•Proceedings Article
Block-Level Security for Network-Attached Disks
Marcos K. Aguilera,Minwen Ji,Mark Lillibridge,John MacCormick,Erwin Oertli,Dave Andersen,Michael Burrows,Timothy Mann,Chandramohan A. Thekkath +8 more
- 31 Mar 2003
TL;DR: The design enforces security using the well-known idea of self-describing capabilities, with two novel features that limit the need for memory on secure NADs: a scheme to manage revocations based on capability groups, and a replay-detection method using Bloom filters.
•Proceedings Article
Timing-accurate Storage Emulation
John Linwood Griffin,Jiri Schindler,Steven W. Schlosser,John S. Bucy,Gregory R. Ganger +4 more
- 28 Jan 2002
TL;DR: A prototype of a timing-accurate storage emulator, called the Memulator, is described and shown to produce service times within 2% of those computed by its component simulator for over 99% of requests.
Efficient AES implementations on ASICs and FPGAs
Norbert Pramstaller,Stefan Mangard,Sandra Dominikus,Johannes Wolkerstorfer +3 more
- 10 May 2004
TL;DR: Two AES hardware architectures are presented: one for ASICs and one for FPGAs, both of which utilize the similarities of encryption and decryption to provide a high throughput using only a relatively small area.
62