Skip to main content

Space-Efficient Block Storage Integrity

Publication ,  Conference
Oprea, A; Reiter, MK; Yang, K
Published in: Proceedings of the Symposium on Network and Distributed System Security, NDSS 2005
January 1, 2005

We present new methods to provide block-level integrity in encrypted storage systems, i.e., so that a client will detect the modification of data blocks by an untrusted storage server. We present cryptographic definitions for this setting, and develop solutions that change neither the block size nor the number of sectors accessed, an important consideration for modern storage systems. In order to achieve this, a trusted client component maintains state with which it can authenticate blocks returned by the storage server, and we explore techniques for minimizing the size of this state. We demonstrate a scheme that provably implements basic block integrity (informally, that any block accepted was previously written), that exhibits a tradeoff between the level of security and the additional client's storage overhead, and that in empirical evaluations requires an average of only 0.01 bytes per 1024-byte block. We extend this to a scheme that implements integrity resistant to replay attacks (informally, that any block accepted was the last block written to that address) using only 1.82 bytes per block, on average, in our one-month long empirical tests.

Duke Scholars

Published In

Proceedings of the Symposium on Network and Distributed System Security, NDSS 2005

Publication Date

January 1, 2005
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Oprea, A., Reiter, M. K., & Yang, K. (2005). Space-Efficient Block Storage Integrity. In Proceedings of the Symposium on Network and Distributed System Security, NDSS 2005.
Oprea, A., M. K. Reiter, and K. Yang. “Space-Efficient Block Storage Integrity.” In Proceedings of the Symposium on Network and Distributed System Security, NDSS 2005, 2005.
Oprea A, Reiter MK, Yang K. Space-Efficient Block Storage Integrity. In: Proceedings of the Symposium on Network and Distributed System Security, NDSS 2005. 2005.
Oprea, A., et al. “Space-Efficient Block Storage Integrity.” Proceedings of the Symposium on Network and Distributed System Security, NDSS 2005, 2005.
Oprea A, Reiter MK, Yang K. Space-Efficient Block Storage Integrity. Proceedings of the Symposium on Network and Distributed System Security, NDSS 2005. 2005.

Published In

Proceedings of the Symposium on Network and Distributed System Security, NDSS 2005

Publication Date

January 1, 2005