信息安全研究 ›› 2017, Vol. 3 ›› Issue (4): 339-343.

• 学术论文 • 上一篇    下一篇

基于可信计算的分布式存储的数据保护方法

侯伟超   

  1. 大唐高鸿信安(浙江)信息科技有限公司北京100010
  • 收稿日期:2017-04-13 出版日期:2017-04-13 发布日期:2017-04-13
  • 通讯作者: 侯伟超
  • 作者简介:侯伟超 硕士,软件工程师,主要研究方向为分布式存储、分布式计算.

A Data Protection Method Based on Trusted Computing in Distributed Storage

  • Received:2017-04-13 Online:2017-04-13 Published:2017-04-13

摘要: 随着数据时代的到来,数据安全也成为一个越来越重要的主题.在此提出了一种基于可信计算技术的分布式存储系统的数据保护方法.分布式存储系统结构包括了客户端,以及负责记录或者以分布式算法映射数据到实际存储节点的元数据服务器模块.系统使用具有可信增强模块的服务器作为数据以及元数据服务器.为了验证存储系统中各服务器的身份,以及客户端用户的身份,系统增加了认证可信状态的认证中心,该认证中心模块同样运行在具有可信增强模块的服务器上.该数据保护方案是从可信计算技术出发,为分布式存储系统提供了一套行之有效的保护机制.

关键词: 数据安全, 分布式存储系统, 可信计算技术, 认证中心, 密钥管理

Abstract: With the advent of the data age, data security has become more and more important. This paper presents a data protection method based on trusted computing technology in distributed storage system. The distributed storage system architecture includes clients, data servers and metadata servers that records or maps data to a real storage node based on a distributed algorithm. The distributed storage system runs data and metadata servers on machines which support trusted computing technology. In order to verify the identity of each server in the storage system and the identity of users, the system adds an authentication center to maintain the trusted status. The authentication center runs on the server with trusted computing functions. The data protection scheme proposed in this paper provides a set of effective protection mechanism based on the trusted computing technology for distributed storage system.

Key words: data security, distributed storage system, trusted computing technology, authentication center, key management