Capability based Secure Access Control to Networked Storage Devices

Michael Factor, Dalit Naor, Eran Rom, Julian Satran · 2007

Today, access control security for storage area networks (zoning and masking) is implemented by mechanisms that are access rules of the form: A requests coming from a are inherently insecure, and are tied to the physical net node connected to port a, can get responses from a node work components. However, what we want to secure is at a higher logical level independent of the transport network; raising security to a logical level simplifies management, provides a more natural fit to a virtualized infrastructure, and enables a finer grained access control. In this paper, ages can access which persistent storage. From this basic we describe the problems with existing access control se problem stem several concrete issues. For instance, since curity solutions, and present our approach which leverages access is tied to ports, changing the physical connection of the OSD (Object-based Storage Device) security model to a node requires updating the SAN security configmation. provide a logical, cryptographically secured, in-band ac This is particularly problematic in a world of compute vir cess control for today's existing devices. We then show tualization, where virtual machines co-exist inside the same how this model can easily be integrated into existing sys physical machine sharing physical resources, and migrate tems and demonstrate that this in-band security mechanism between physical machines. Even without virtualization, has negligible performance impact while simplifying this mixing of levels of abstraction is a recipe for manageagement, providing a clean match to compute virtualization and enabling fine grained access control.

Read the paper · More papers on PaperTik