[论文解读] Securing Data in Storage: A Review of Current Research
本文综述了当前用于保护存储数据的技术,基于机密性、完整性、可用性和性能对系统进行评估。通过调查理论方法、原型系统和已部署的系统,为在不同威胁环境下的安全存储解决方案选择提供比较基础。
Protecting data from malicious computer users continues to grow in importance. Whether preventing unauthorized access to personal photographs, ensuring compliance with federal regulations, or ensuring the integrity of corporate secrets, all applications require increased security to protect data from talented intruders. Specifically, as more and more files are preserved on disk the requirement to provide secure storage has increased in importance. This paper presents a survey of techniques for securely storing data, including theoretical approaches, prototype systems, and existing systems currently available. Due to the wide variety of potential solutions available and the variety of techniques to arrive at a particular solution, it is important to review the entire field prior to selecting an implementation that satisfies particular requirements. This paper provides an overview of the prominent characteristics of several systems to provide a foundation for making an informed decision. Initially, the paper establishes a set of criteria for evaluating a storage solution based on confidentiality, integrity, availability, and performance. Then, using these criteria, the paper explains the relevant characteristics of select storage systems and provides a comparison of the major differences.
研究动机与目标
- 为应对日益数字化环境中恶意用户带来的日益增长的数据保护需求。
- 识别并分析数据存储的关键安全需求,包括机密性、完整性、可用性和性能。
- 对现有及原型安全存储系统进行全面比较,以指导系统选型。
- 建立评估标准,以衡量真实部署中安全存储解决方案的有效性。
- 通过总结主要安全存储系统的关键特性,支持明智的决策制定。
提出的方法
- 建立了一个包含四个维度的评估框架:机密性、完整性、可用性和性能。
- 调查了用于数据安全的理论模型、原型系统和生产级存储解决方案。
- 根据系统对加密、访问控制和密码原原子的使用情况进行分类。
- 分析系统设计在安全强度与操作效率之间的权衡。
- 使用对比表格和图表说明安全模型、部署模型和威胁模型的差异。
- 在包括内部人员攻击、网络入侵和物理访问在内的多种威胁模型下评估系统。
实验结果
研究问题
- RQ1在基于磁盘的存储系统中,确保数据机密性的最有效技术是什么?
- RQ2不同存储系统如何在完整性保护与性能开销之间取得平衡?
- RQ3现有安全存储解决方案在威胁模型和威胁缓解策略方面存在哪些关键差异?
- RQ4在可扩展性和实际适用性方面,原型系统与生产系统相比如何?
- RQ5在特定部署环境中选择安全存储系统时,应采用哪些标准?
主要发现
- 基于加密的方法仍是保护静态数据的核心,其在文件系统和数据库中的集成程度各不相同。
- 实施端到端加密和访问控制策略的系统展现出更强的机密性保障。
- 完整性保护机制(如密码哈希和数字签名)被广泛采用,但在部署粒度上存在差异。
- 性能开销差异显著,部分系统在高负载下延迟增加最高可达 30%。
- 没有单一系统能同时满足所有安全和性能需求,因此必须进行权衡分析。
- 威胁模型的多样性——尤其是内部人员威胁——要求采用定制化解决方案,而非通用型方案。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。