Skip to main navigation Skip to search Skip to main content

Round-trip privacy with NFSv4

  • Stony Brook University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

4 Scopus citations

Abstract

With the advent of NFS version 4, NFS security is more important than ever. This is because a main goal of the NFSv4 protocol is suitability for use on the Internet, whereas previous versions were used mainly on private networks. To address these security concerns, the NFSv4 protocol utilizes the RPCSEC GSS protocol and allows clients and servers to negotiate security at mount-time. However, this provides privacy only while data is traveling over the wire. We believe that file servers accessible over the Internet should contain only encrypted data. We present a round-trip privacy scheme for NFSv4, where clients encrypt file data for write requests, and decrypt the data for read requests. The data stored by the server on behalf of the clients is encrypted. This helps ensure privacy if the server or storage is stolen or compromised. As the NFSv4 protocol was designed with extensibility, it is the ideal place to add roundtrip privacy. In addition to providing a higher level of security than only over-the-wire encryption, our technique is more efficient, as the server is relieved from performing encryption and decryption. We developed a prototype of our round-trip privacy scheme. In our performance evaluation, we saw throughput increases of up to 24%, as well as good scalability.

Original languageEnglish
Title of host publicationStorageSS'07 - Proceedings of the 2007 ACM Workshop on Storage Security and Survivability
Pages1-6
Number of pages6
DOIs
StatePublished - 2007
Event2007 ACM Workshop on Storage Security and Survivability, StorageSS'07 - Alexandria, VA, United States
Duration: Oct 29 2007Oct 29 2007

Publication series

NameStorageSS'07 - Proceedings of the 2007 ACM Workshop on Storage Security and Survivability

Conference

Conference2007 ACM Workshop on Storage Security and Survivability, StorageSS'07
Country/TerritoryUnited States
CityAlexandria, VA
Period10/29/0710/29/07

Keywords

  • Encryption
  • NFSv4
  • Round-trip

Fingerprint

Dive into the research topics of 'Round-trip privacy with NFSv4'. Together they form a unique fingerprint.

Cite this