Back to Search
Start Over
Access Control Conflict Resolution in Distributed File Systems using CRDTs
- Source :
- PaPoC@EuroSys
- Publication Year :
- 2021
- Publisher :
- ACM, 2021.
-
Abstract
- Distributed file systems have become an essential service for sharing data among users. An important aspect of a file system is its ability to keep its contents secure from unauthorized access. To investigate the interplay of security and consistency in distributed file systems, we formalize the three properties related to data security, namely confidentiality, integrity and accessibility. Based on these properties, we provide an impossibility result that indicates that these properties cannot be achieved together in a highly-available partition-tolerant setting. We further discuss a CRDT-based model, implementing the traditional POSIX access control policy, that guarantees confidentiality and integrity while precluding accessibility only in rare situations. Our conclusion is that the POSIX policies are not suitable in a distributed system setting, but that a more fine-grained model is required to obtain the security semantics that reflect the users' intention.
- Subjects :
- File system
Conflict-free replicated data type
Computer science
business.industry
Data security
020206 networking & telecommunications
Access control
02 engineering and technology
computer.software_genre
Computer security
Consistency (database systems)
POSIX
020204 information systems
0202 electrical engineering, electronic engineering, information engineering
Confidentiality
business
Distributed File System
computer
Subjects
Details
- Database :
- OpenAIRE
- Journal :
- Proceedings of the 8th Workshop on Principles and Practice of Consistency for Distributed Data
- Accession number :
- edsair.doi...........2c8c65576c333118440f363645237a10
- Full Text :
- https://doi.org/10.1145/3447865.3457970