SDSuPK: Secured data sharing using proxy Kerberos to improve Openstack Swift security

Research output: Contribution to book/Conference proceedings/Anthology/ReportConference contributionContributed

Contributors

  • Sima Attar Khorasani - , Alzahra University (Author)
  • Dr. Reza Azmi - , Alzahra University (Author)
  • Dr. Vajihe Sabeti - , Alzahra University (Author)

Abstract

Cloud computing is rather new, and there're, of course, concerns like data-protection. This technology is developing as a standard for data-sharing on remote storages. Cloud has been able to convince users and companies' owners to transfer their data to Cloud so they can use Cloud resources and reduce their costs. Due to importance of data for its owners, there's always concern about security. When the amount of data sent to Cloud increases, giving permission to users and taking it back becomes a challenging topic. Also, as the number of users increases, a large workload lies on Cloud server due to authentication, which is a serious challenge of Cloud. In this paper, we focus on a trusted third-party mechanism, namely Kerberos, to address the mentioned issues. These mechanisms based on tickets are an effective way to ensure user authentication and authorization and force the least interaction and workload to the Cloud server. We designed a mechanism based on Kerberos that completely fits into Openstack Object Storage(Swift) to authenticate and authorize users who desire to access the shared objects. We implement our mechanism and overall system, and evaluate its security and performance. Our results show that our mechanism is practical and efficient.

Details

Original languageEnglish
Title of host publication2017 7th International Conference on Computer and Knowledge Engineering (ICCKE)
Pages77-83
Publication statusPublished - Oct 2017
Peer-reviewedNo
Externally publishedYes

External IDs

Scopus 85046470121