Academia.eduAcademia.edu

A two layered approach for securing an object store network

2003, First International IEEE Security in Storage Workshop, 2002. Proceedings.

Abstract

Storage Area Networks (SAN) are based on direct interaction between clients and storage servers exposing the storage server to network attacks. Giving the client direct access to the storage servers requires verification that the client requests conform with the system protection policy. Today, the only available solutions enforce access control at the granularity of entire storage servers. This is an outcome of the way storage servers abstract storage: an array of fixed size blocks. The alternative approach of providing access control at the granularity of blocks is infeasiblethere are too many active blocks in the server. Object stores (r.g., the NASD system ) provide means to address these issues. An object store control unit presents an abstraction of a dynamic collection of objects, each can be seen as a different array of blocks, thus providing the basis for providing protection at an object level.