Let the Cloud Watch Over Your IoT File Systems

02/17/2019
by   Liwei Guo, et al.
0

Smart devices produce security-sensitive data and keep them in on-device storage for persistence. The current storage stack on smart devices, however, offers weak security guarantees: not only because the stack depends on a vulnerable commodity OS, but also because smart device deployment is known weak on security measures. To safeguard such data on smart devices, we present a novel storage stack architecture that i) protects file data in a trusted execution environment (TEE); ii) outsources file system logic and metadata out of TEE; iii) running a metadata-only file system replica in the cloud for continuously verifying the on-device file system behaviors. To realize the architecture, we build Overwatch, aTrustZone-based storage stack. Overwatch addresses unique challenges including discerning metadata at fine grains, hiding network delays, and coping with cloud disconnection. On a suite of three real-world applications, Overwatch shows moderate security overheads.

READ FULL TEXT
research
09/14/2020

Revealing the Weaknesses of File Sharing System on Cloud Storages

Cloud storage provides the simpler way to share the files privately and ...
research
05/29/2023

Securing Cloud File Systems using Shielded Execution

Cloud file systems offer organizations a scalable and reliable file stor...
research
02/25/2021

BPF for storage: an exokernel-inspired approach

The overhead of the kernel storage path accounts for half of the access ...
research
07/05/2022

Learnings from an Under the Hood Analysis of an Object Storage Node IO Stack

Conventional object-stores are built on top of traditional OS storage st...
research
05/31/2019

DFS: A Dataset File System for Data Discovering Users

Many research questions can be answered quickly and efficiently using da...
research
10/17/2022

RIO: Order-Preserving and CPU-Efficient Remote Storage Access

Modern NVMe SSDs and RDMA networks provide dramatically higher bandwidth...
research
07/21/2023

Understanding (Un)Written Contracts of NVMe ZNS Devices with zns-tools

Operational and performance characteristics of flash SSDs have long been...

Please sign up or login with your details

Forgot password? Click here to reset