A comparison of secure multi-tenancy architectures for filesystem storage clouds

  • Authors:
  • Anil Kurmus;Moitrayee Gupta;Roman Pletka;Christian Cachin;Robert Haas

  • Affiliations:
  • IBM Research, Zurich;Department of Computer Science and Engineering, UCSD;IBM Research, Zurich;IBM Research, Zurich;IBM Research, Zurich

  • Venue:
  • Middleware'11 Proceedings of the 12th ACM/IFIP/USENIX international conference on Middleware
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

A filesystem-level storage cloud offers network-filesystem access to multiple customers at low cost over the Internet. In this paper, we investigate two alternative architectures for achieving multi-tenancy securely and efficiently in such storage cloud services. They isolate customers in virtual machines at the hypervisor level and through mandatory access-control checks in one shared operating-system kernel, respectively. We compare and discuss the practical security guarantees of these architectures. We have implemented both approaches and compare them using performance measurements we obtained.