Visible to the public Data Protection in OpenStack

TitleData Protection in OpenStack
Publication TypeConference Paper
Year of Publication2017
AuthorsBenjamin, B., Coffman, J., Esiely-Barrera, H., Farr, K., Fichter, D., Genin, D., Glendenning, L., Hamilton, P., Harshavardhana, S., Hom, R., Poulos, B., Reller, N.
Conference Name2017 IEEE 10th International Conference on Cloud Computing (CLOUD)
ISBN Number978-1-5386-1993-3
Keywordsbasic security controls, cloud computing, cloud providers, data protection, Data security, Encryption, Hardware, human factors, Metrics, Neutrons, open source cloud computing platform, Open Source Software, OpenStack range, operational cloud deployment, Organizations, Pervasive Computing Security, pubcrawl, public domain software, Resiliency, Scalability, security analysis, security features, security of data, storage encryption, virtual machine images, virtual machines
Abstract

As cloud computing becomes increasingly pervasive, it is critical for cloud providers to support basic security controls. Although major cloud providers tout such features, relatively little is known in many cases about their design and implementation. In this paper, we describe several security features in OpenStack, a widely-used, open source cloud computing platform. Our contributions to OpenStack range from key management and storage encryption to guaranteeing the integrity of virtual machine (VM) images prior to boot. We describe the design and implementation of these features in detail and provide a security analysis that enumerates the threats that each mitigates. Our performance evaluation shows that these security features have an acceptable cost-in some cases, within the measurement error observed in an operational cloud deployment. Finally, we highlight lessons learned from our real-world development experiences from contributing these features to OpenStack as a way to encourage others to transition their research into practice.

URLhttps://ieeexplore.ieee.org/document/8030634/
DOI10.1109/CLOUD.2017.77
Citation Keybenjamin_data_2017