Data Protection in OpenStack
Title | Data Protection in OpenStack |
Publication Type | Conference Paper |
Year of Publication | 2017 |
Authors | Benjamin, B., Coffman, J., Esiely-Barrera, H., Farr, K., Fichter, D., Genin, D., Glendenning, L., Hamilton, P., Harshavardhana, S., Hom, R., Poulos, B., Reller, N. |
Conference Name | 2017 IEEE 10th International Conference on Cloud Computing (CLOUD) |
ISBN Number | 978-1-5386-1993-3 |
Keywords | basic security controls, cloud computing, cloud providers, data protection, Data security, Encryption, Hardware, human factors, Metrics, Neutrons, open source cloud computing platform, Open Source Software, OpenStack range, operational cloud deployment, Organizations, Pervasive Computing Security, pubcrawl, public domain software, Resiliency, Scalability, security analysis, security features, security of data, storage encryption, virtual machine images, virtual machines |
Abstract | As cloud computing becomes increasingly pervasive, it is critical for cloud providers to support basic security controls. Although major cloud providers tout such features, relatively little is known in many cases about their design and implementation. In this paper, we describe several security features in OpenStack, a widely-used, open source cloud computing platform. Our contributions to OpenStack range from key management and storage encryption to guaranteeing the integrity of virtual machine (VM) images prior to boot. We describe the design and implementation of these features in detail and provide a security analysis that enumerates the threats that each mitigates. Our performance evaluation shows that these security features have an acceptable cost-in some cases, within the measurement error observed in an operational cloud deployment. Finally, we highlight lessons learned from our real-world development experiences from contributing these features to OpenStack as a way to encourage others to transition their research into practice. |
URL | https://ieeexplore.ieee.org/document/8030634/ |
DOI | 10.1109/CLOUD.2017.77 |
Citation Key | benjamin_data_2017 |
- operational cloud deployment
- virtual machines
- virtual machine images
- storage encryption
- security of data
- security features
- Security analysis
- Scalability
- Resiliency
- public domain software
- pubcrawl
- Pervasive Computing Security
- Organizations
- basic security controls
- OpenStack range
- Open Source Software
- open source cloud computing platform
- Neutrons
- Metrics
- Human Factors
- Hardware
- encryption
- Data Security
- Data protection
- cloud providers
- Cloud Computing