Securing Cloud File Systems with Trusted Execution

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Burke, Quinn, Beugin, Yohan, Hoak, Blaine, King, Rachel, Pauley, Eric, Sheatsley, Ryan, Yu, Mingli, He, Ting, La Porta, Thomas, McDaniel, Patrick
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917793360773120
author Burke, Quinn
Beugin, Yohan
Hoak, Blaine
King, Rachel
Pauley, Eric
Sheatsley, Ryan
Yu, Mingli
He, Ting
La Porta, Thomas
McDaniel, Patrick
author_facet Burke, Quinn
Beugin, Yohan
Hoak, Blaine
King, Rachel
Pauley, Eric
Sheatsley, Ryan
Yu, Mingli
He, Ting
La Porta, Thomas
McDaniel, Patrick
contents Cloud file systems offer organizations a scalable and reliable file storage solution. However, cloud file systems have become prime targets for adversaries, and traditional designs are not equipped to protect organizations against the myriad of attacks that may be initiated by a malicious cloud provider, co-tenant, or end-client. Recently proposed designs leveraging cryptographic techniques and trusted execution environments (TEEs) still force organizations to make undesirable trade-offs, consequently leading to either security, functional, or performance limitations. In this paper, we introduce BFS, a cloud file system that leverages the security capabilities provided by TEEs to bootstrap new security protocols that deliver strong security guarantees, high-performance, and a transparent POSIX-like interface to clients. BFS delivers stronger security guarantees and up to a 2.5X speedup over a state-of-the-art secure file system. Moreover, compared to the industry standard NFS, BFS achieves up to 2.2X speedups across micro-benchmarks and incurs <1X overhead for most macro-benchmark workloads. BFS demonstrates a holistic cloud file system design that does not sacrifice an organizations' security yet can embrace all of the functional and performance advantages of outsourcing.
format Preprint
id arxiv_https___arxiv_org_abs_2305_18639
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Securing Cloud File Systems with Trusted Execution
Burke, Quinn
Beugin, Yohan
Hoak, Blaine
King, Rachel
Pauley, Eric
Sheatsley, Ryan
Yu, Mingli
He, Ting
La Porta, Thomas
McDaniel, Patrick
Cryptography and Security
Operating Systems
Cloud file systems offer organizations a scalable and reliable file storage solution. However, cloud file systems have become prime targets for adversaries, and traditional designs are not equipped to protect organizations against the myriad of attacks that may be initiated by a malicious cloud provider, co-tenant, or end-client. Recently proposed designs leveraging cryptographic techniques and trusted execution environments (TEEs) still force organizations to make undesirable trade-offs, consequently leading to either security, functional, or performance limitations. In this paper, we introduce BFS, a cloud file system that leverages the security capabilities provided by TEEs to bootstrap new security protocols that deliver strong security guarantees, high-performance, and a transparent POSIX-like interface to clients. BFS delivers stronger security guarantees and up to a 2.5X speedup over a state-of-the-art secure file system. Moreover, compared to the industry standard NFS, BFS achieves up to 2.2X speedups across micro-benchmarks and incurs <1X overhead for most macro-benchmark workloads. BFS demonstrates a holistic cloud file system design that does not sacrifice an organizations' security yet can embrace all of the functional and performance advantages of outsourcing.
title Securing Cloud File Systems with Trusted Execution
topic Cryptography and Security
Operating Systems
url https://arxiv.org/abs/2305.18639