High-performance reconfigurable encryption scheme for distributed storage

As the world embraces the digital economy and enters an information society, data has emerged as a critical production factor.The collection, processing, and storage of data have become increasingly prevalent.Distributed storage systems, known for their efficiency, are widely used in various data fi...

Full description

Bibliographic Details
Main Author: Zhihua FENG, Yuxuan ZHANG, Chong LUO, Jianing WANG
Format: Article
Language:English
Published: POSTS&TELECOM PRESS Co., LTD 2023-10-01
Series:网络与信息安全学报
Subjects:
Online Access:https://www.infocomm-journal.com/cjnis/CN/10.11959/j.issn.2096-109x.2023072
_version_ 1797262478968619008
author Zhihua FENG, Yuxuan ZHANG, Chong LUO, Jianing WANG
author_facet Zhihua FENG, Yuxuan ZHANG, Chong LUO, Jianing WANG
author_sort Zhihua FENG, Yuxuan ZHANG, Chong LUO, Jianing WANG
collection DOAJ
description As the world embraces the digital economy and enters an information society, data has emerged as a critical production factor.The collection, processing, and storage of data have become increasingly prevalent.Distributed storage systems, known for their efficiency, are widely used in various data fields.However, as the scale of data storage continues to expand, distributed storage faces more significant security risks, such as information leakage and data destruction.These challenges drive the need for innovative advancements in big data distributed storage security technology and foster the integration of domestic cryptographic technology with computing storage technology.This work focused on addressing security issues, particularly information leakage, in distributed storage nodes.A dynamic and reconfigurable encryption storage solution was proposed, which considered the requirements for encryption performance and flexibility.A high-performance reconfigurable cryptographic module was designed based on the bio mapping framework.Based on this module, multiple storage pools equipped with different cryptographic algorithms were constructed to facilitate high-performance encryption and decryption operations on hard disk data.The scheme also enabled dynamic switching of cryptographic algorithms within the storage pools.A cryptographic protocol with remote online loading functions for cryptographic algorithms and keys was developed to meet the unified management and convenient security update requirements of reconfigurable cryptographic modules in various storage nodes.Furthermore, the scheme implemented fine-grained data encryption protection and logical security isolation functions based on cryptographic reconstruction technology.Experimental results demonstrate that the performance loss of this scheme for encryption protection and security isolation of stored data is approximately 10%.It provides a technical approach for distributed storage systems to meet the cryptographic application technology requirements outlined in GB/T 39786-2021 “Information Security Technology-Basic Requirements for Cryptography Applications” Level 3 and above in terms of device and computing security, application and data security.
first_indexed 2024-04-24T23:57:46Z
format Article
id doaj.art-f6544292c3c949e58f674db4c27b174c
institution Directory Open Access Journal
issn 2096-109X
language English
last_indexed 2024-04-24T23:57:46Z
publishDate 2023-10-01
publisher POSTS&TELECOM PRESS Co., LTD
record_format Article
series 网络与信息安全学报
spelling doaj.art-f6544292c3c949e58f674db4c27b174c2024-03-14T11:55:14ZengPOSTS&TELECOM PRESS Co., LTD网络与信息安全学报2096-109X2023-10-0195597010.11959/j.issn.2096-109x.2023072High-performance reconfigurable encryption scheme for distributed storageZhihua FENG, Yuxuan ZHANG, Chong LUO, Jianing WANGAs the world embraces the digital economy and enters an information society, data has emerged as a critical production factor.The collection, processing, and storage of data have become increasingly prevalent.Distributed storage systems, known for their efficiency, are widely used in various data fields.However, as the scale of data storage continues to expand, distributed storage faces more significant security risks, such as information leakage and data destruction.These challenges drive the need for innovative advancements in big data distributed storage security technology and foster the integration of domestic cryptographic technology with computing storage technology.This work focused on addressing security issues, particularly information leakage, in distributed storage nodes.A dynamic and reconfigurable encryption storage solution was proposed, which considered the requirements for encryption performance and flexibility.A high-performance reconfigurable cryptographic module was designed based on the bio mapping framework.Based on this module, multiple storage pools equipped with different cryptographic algorithms were constructed to facilitate high-performance encryption and decryption operations on hard disk data.The scheme also enabled dynamic switching of cryptographic algorithms within the storage pools.A cryptographic protocol with remote online loading functions for cryptographic algorithms and keys was developed to meet the unified management and convenient security update requirements of reconfigurable cryptographic modules in various storage nodes.Furthermore, the scheme implemented fine-grained data encryption protection and logical security isolation functions based on cryptographic reconstruction technology.Experimental results demonstrate that the performance loss of this scheme for encryption protection and security isolation of stored data is approximately 10%.It provides a technical approach for distributed storage systems to meet the cryptographic application technology requirements outlined in GB/T 39786-2021 “Information Security Technology-Basic Requirements for Cryptography Applications” Level 3 and above in terms of device and computing security, application and data security.https://www.infocomm-journal.com/cjnis/CN/10.11959/j.issn.2096-109x.2023072distributed storage encryptionreconfigurable encryption technologyblock device encryptionalgorithm online loadinglogical safety isolation
spellingShingle Zhihua FENG, Yuxuan ZHANG, Chong LUO, Jianing WANG
High-performance reconfigurable encryption scheme for distributed storage
网络与信息安全学报
distributed storage encryption
reconfigurable encryption technology
block device encryption
algorithm online loading
logical safety isolation
title High-performance reconfigurable encryption scheme for distributed storage
title_full High-performance reconfigurable encryption scheme for distributed storage
title_fullStr High-performance reconfigurable encryption scheme for distributed storage
title_full_unstemmed High-performance reconfigurable encryption scheme for distributed storage
title_short High-performance reconfigurable encryption scheme for distributed storage
title_sort high performance reconfigurable encryption scheme for distributed storage
topic distributed storage encryption
reconfigurable encryption technology
block device encryption
algorithm online loading
logical safety isolation
url https://www.infocomm-journal.com/cjnis/CN/10.11959/j.issn.2096-109x.2023072
work_keys_str_mv AT zhihuafengyuxuanzhangchongluojianingwang highperformancereconfigurableencryptionschemefordistributedstorage