Integrity checking in cryptographic file systems with constant trusted storage

USENIX Security(2007)

引用 52|浏览21
暂无评分
摘要
In this paper we propose two new constructions for protecting the integrity of files in cryptographic file systems. Our constructions are designed to exploit two characteristics of many file-system workloads, namely low entropy of file contents and high sequentiality of file block writes. At the same time, our approaches maintain the best features of the most commonly used algorithm today (Merkle trees), including defense against replay of stale (previously overwritten) blocks and a small, constant amount of trusted storage per file. Via implementations in the EncFS cryptographic file system, we evaluate the performance and storage requirements of our new constructions compared to those of Merkle trees. We conclude with guidelines for choosing the best integrity algorithm depending on typical application workload.
更多
查看译文
关键词
merkle tree,best feature,best integrity algorithm,constant amount,storage requirement,encfs cryptographic file system,cryptographic file system,integrity checking,file content,new construction,file block,merkle trees
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要