网络与信息安全学报 ›› 2023, Vol. 9 ›› Issue (5): 59-70.doi: 10.11959/j.issn.2096-109x.2023072

• 学术论文 • 上一篇    

面向分布式存储的高性能可重构加密方案

冯志华, 张宇轩, 罗重, 王佳宁   

  1. 北京计算机技术及应用研究所,北京 100854
  • 修回日期:2023-03-21 出版日期:2023-10-01 发布日期:2023-10-01
  • 作者简介:冯志华(1979− ),男,湖北孝感人,博士,北京计算机技术及应用研究所研究员,主要研究方向为计算机及信息系统安全
    张宇轩(1998− ),男,河北石家庄人,北京计算机技术及应用研究所助理工程师,主要研究方向为计算机应用技术
    罗重(1994− ),男,湖北孝感人,北京计算机技术及应用研究所工程师,主要研究方向为计算机应用技术
    王佳宁(1980− ),男,河北安平人,北京计算机技术及应用研究所高级工程师,主要研究方向为密码管理理论、密码应用理论、密码工程
  • 基金资助:
    国家重点研发计划(2018YFB220030);山东省重点研发计划(2022CXGC010108)

High-performance reconfigurable encryption scheme for distributed storage

Zhihua FENG, Yuxuan ZHANG, Chong LUO, Jianing WANG   

  1. Beijing Institute of Computer Technology and Applications, Beijing 100854, China
  • Revised:2023-03-21 Online:2023-10-01 Published:2023-10-01
  • Supported by:
    The National Key R&D Program of China(2018YFB220030);Key R&D Program of Shandong Province, China(2022CXGC010108)

摘要:

全球进入以数字经济为主导的信息社会,数据成为关键生产要素,当今越来越多的数据被收集、处理和存储,分布式存储系统作为一种高效的存储架构在各数据领域得到广泛应用。然而,随着数据存储规模的不断扩大,分布式存储面临着信息泄露、数据破坏等更深层次的安全风险挑战。这些挑战将推动大数据分布式存储安全技术的创新变革,促进了国产密码技术和计算存储技术的融合。针对分布式存储节点数据信息泄露等安全问题,考虑到分布式存储加密性能与灵活性等需求,提出一种动态可重构加密存储解决方案。该方案设计了基于bio映射框架的高性能可重构密码模块,在此基础上构建多个配用不同密码算法的存储池,实现高性能硬盘数据加解密操作和存储池密码算法动态切换,并开发了具有密码算法和密钥远程在线加载功能的密码协议,满足各存储节点可重构密码模块统一管理与便捷安全更新需求,实现基于密码重构技术的数据细粒度加密保护和逻辑安全隔离功能。实验结果表明,该方案对存储数据进行加密保护与安全隔离的性能损耗约10%,可为分布式存储系统达到GB/T 39786-202《1 信息安全技术 信息系统密码应用基本要求》第三级及以上在设备和计算安全、应用和数据安全等方面提出的密码应用技术要求提供技术途径。

关键词: 分布式存储加密, 可重构加密技术, 块设备加密, 算法在线加载, 逻辑安全隔离

Abstract:

As the world embraces the digital economy and enters an information society, data has emerged as a critical production factor.The collection, processing, and storage of data have become increasingly prevalent.Distributed storage systems, known for their efficiency, are widely used in various data fields.However, as the scale of data storage continues to expand, distributed storage faces more significant security risks, such as information leakage and data destruction.These challenges drive the need for innovative advancements in big data distributed storage security technology and foster the integration of domestic cryptographic technology with computing storage technology.This work focused on addressing security issues, particularly information leakage, in distributed storage nodes.A dynamic and reconfigurable encryption storage solution was proposed, which considered the requirements for encryption performance and flexibility.A high-performance reconfigurable cryptographic module was designed based on the bio mapping framework.Based on this module, multiple storage pools equipped with different cryptographic algorithms were constructed to facilitate high-performance encryption and decryption operations on hard disk data.The scheme also enabled dynamic switching of cryptographic algorithms within the storage pools.A cryptographic protocol with remote online loading functions for cryptographic algorithms and keys was developed to meet the unified management and convenient security update requirements of reconfigurable cryptographic modules in various storage nodes.Furthermore, the scheme implemented fine-grained data encryption protection and logical security isolation functions based on cryptographic reconstruction technology.Experimental results demonstrate that the performance loss of this scheme for encryption protection and security isolation of stored data is approximately 10%.It provides a technical approach for distributed storage systems to meet the cryptographic application technology requirements outlined in GB/T 39786-2021 “Information Security Technology-Basic Requirements for Cryptography Applications” Level 3 and above in terms of device and computing security, application and data security.

Key words: distributed storage encryption, reconfigurable encryption technology, block device encryption, algorithm online loading, logical safety isolation

中图分类号: 

No Suggested Reading articles found!