Security vs Performance: Tradeoffs using a Trust Framework
- 25 April 2005
- conference paper
- Published by Institute of Electrical and Electronics Engineers (IEEE)
- p. 270-277
- https://doi.org/10.1109/msst.2005.31
Abstract
We present an architecture of a trust framework that can be used to intelligently tradeoff between security and performance in a SAN file system. The primary idea is to differentiate between various clients in the system based on their trustworthiness and provide them with differing levels of security and performance. Client trustworthiness reflects its expected behavior and is evaluated in an online fashion using a customizable trust model. We also describe the interface of the trust framework with an example block level security solution for an out-of-band virtualization based SAN file system (SAN FS). The proposed framework can be easily extended to provide differential treatment based on data sensitivity, using a configurable parameter of the trust model. This allows associating stringent security requirements for more sensitive data, while trading off security for better performance for less critical data, a situation regularly desired in an enterprise.Keywords
This publication has 9 references indexed in Scilit:
- Supporting trust in virtual communitiesPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2005
- A reputation-based trust model for peer-to-peer e-commerce communitiesPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2003
- Towards an object storePublished by Institute of Electrical and Electronics Engineers (IEEE) ,2003
- The Eigentrust algorithm for reputation management in P2P networksPublished by Association for Computing Machinery (ACM) ,2003
- TrustMe: anonymous management of trust relationships in decentralized P2P systemsPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2003
- IBM Storage Tank—A heterogeneous scalable SAN file systemIBM Systems Journal, 2003
- Managing trust in a peer-2-peer information systemPublished by Association for Computing Machinery (ACM) ,2001
- Authenticating network attached storageIEEE Micro, 2000
- A cost-effective, high-bandwidth storage architecturePublished by Association for Computing Machinery (ACM) ,1998