Back to Search Start Over

Access Control Conflict Resolution in Distributed File Systems using CRDTs

Authors :
Annette Bieniusa
Ahmad Hussein Rezae
Elena Yanakieva
Michael Youssef
Source :
PaPoC@EuroSys
Publication Year :
2021
Publisher :
ACM, 2021.

Abstract

Distributed file systems have become an essential service for sharing data among users. An important aspect of a file system is its ability to keep its contents secure from unauthorized access. To investigate the interplay of security and consistency in distributed file systems, we formalize the three properties related to data security, namely confidentiality, integrity and accessibility. Based on these properties, we provide an impossibility result that indicates that these properties cannot be achieved together in a highly-available partition-tolerant setting. We further discuss a CRDT-based model, implementing the traditional POSIX access control policy, that guarantees confidentiality and integrity while precluding accessibility only in rare situations. Our conclusion is that the POSIX policies are not suitable in a distributed system setting, but that a more fine-grained model is required to obtain the security semantics that reflect the users' intention.

Details

Database :
OpenAIRE
Journal :
Proceedings of the 8th Workshop on Principles and Practice of Consistency for Distributed Data
Accession number :
edsair.doi...........2c8c65576c333118440f363645237a10
Full Text :
https://doi.org/10.1145/3447865.3457970