Polish National Data Storage. Norbert Meyer, Maciej Brzeźniak, Maciej Stroiński PSNC



Similar documents
National Data Store 2 crypto-clients - demonstration

NDS2 Secure storage, sharing and publishing of data in the NDS

National Data Storage data replication in the network

National Data Storage 2 Secure sharing, publishing and exchanging data

Michał Jankowski Maciej Brzeźniak PSNC

Popular backup/archival service and its application for the archival of the network traffic in the academic network PIONIER

The software platform for storing, preserving and sharing very large data sets.

File Sharing and Network Marketing

Building Storage Service in a Private Cloud

Large Scale Storage. Orlando Richards, Information Services LCFG Users Day, University of Edinburgh 18 th January 2013

Alliance AES Encryption for IBM i Solution Brief

Network Attached Storage. Jinfeng Yang Oct/19/2015

EMC DATA PROTECTION. Backup ed Archivio su cui fare affidamento

SECURITY SUMMIT 06/06/2013 Roma STORAGE FORENSICS. Litiano Piccin (NCDA-NCIE/SAN)

XtreemStore A SCALABLE STORAGE MANAGEMENT SOFTWARE WITHOUT LIMITS YOUR DATA. YOUR CONTROL

DPAD Introduction. EMC Data Protection and Availability Division. Copyright 2011 EMC Corporation. All rights reserved.

How To Back Up A Computer To A Backup On A Hard Drive On A Microsoft Macbook (Or Ipad) With A Backup From A Flash Drive To A Flash Memory (Or A Flash) On A Flash (Or Macbook) On

Flexible Scalable Hardware independent. Solutions for Long Term Archiving

NAS 109 Using NAS with Linux

EMC BACKUP MEETS BIG DATA

2011 FileTek, Inc. All rights reserved. 1 QUESTION

Alliance Key Manager Cloud HSM Frequently Asked Questions

09'Linux Plumbers Conference

Diagram 1: Islands of storage across a digital broadcast workflow

EMC DATA DOMAIN OVERVIEW. Copyright 2011 EMC Corporation. All rights reserved.

Storage Made Easy Enterprise File Share and Sync (EFSS) Cloud Control Gateway Architecture

Workshop on Cloud Services for File Synchronisation and Sharing NOV 2014

Credibly secure cloud storage with elfcloud

WOS OBJECT STORAGE PRODUCT BROCHURE DDN.COM Full Spectrum Object Storage

BlueArc unified network storage systems 7th TF-Storage Meeting. Scale Bigger, Store Smarter, Accelerate Everything

Big Data Unlimited Cloud Storage Atmos Object Storage

IBM Tivoli Storage Manager Version Introduction to Data Protection Solutions IBM

IBM TSM DISASTER RECOVERY BEST PRACTICES WITH EMC DATA DOMAIN DEDUPLICATION STORAGE

IBM Smart Business Storage Cloud

Disaster Recovery Checklist Disaster Recovery Plan for <System One>

IBM Infrastructure for Long Term Digital Archiving

owncloud Architecture Overview

Introduction to Datacenters & the Cloud

Backup and Recovery Solutions for Exadata. Ľubomír Vaňo Principal Sales Consultant

Crittografia e Enterprise Key Management una sfida possibile da affrontare

Advanced Service Platform for e-science. Robert Pękal, Maciej Stroiński, Jan Węglarz (PSNC PL)

The safer, easier way to help you pass any IT exams. Exam : Storage Sales V2. Title : Version : Demo 1 / 5

Architecture and Mode of Operation

Cloudian The Storage Evolution to the Cloud.. Cloudian Inc. Pre Sales Engineering

NETWORK ATTACHED STORAGE DIFFERENT FROM TRADITIONAL FILE SERVERS & IMPLEMENTATION OF WINDOWS BASED NAS

(Scale Out NAS System)

File System Design and Implementation

Long term retention and archiving the challenges and the solution

Storage Virtualization. Andreas Joachim Peters CERN IT-DSS

Object storage in Cloud Computing and Embedded Processing

Compatibility and Support Information Nasuni Corporation Natick, MA

Hitachi Essential NAS Platform, NAS Gateway with High Cost Performance

Storage System: Management of Explosively Increasing Data in Mission-Critical Systems

A Virtual Filer for VMware s Virtual SAN A Maginatics and VMware Joint Partner Brief

In Memory Accelerator for MongoDB

White Paper: 5 Ways Cloud-integrated Storage Reduces Costs

Storage Virtualization from clusters to grid

Meeting Technology Risk Management (TRM) Guidelines from the Monetary Authority of Singapore (MAS)

Boas Betzler. Planet. Globally Distributed IaaS Platform Examples AWS and SoftLayer. November 9, IBM Corporation

Introduction to Gluster. Versions 3.0.x

SCALABLE FILE SHARING AND DATA MANAGEMENT FOR INTERNET OF THINGS

Transporter from Connected Data Date: February 2015 Author: Kerry Dolan, Lab Analyst and Vinny Choinski, Sr. Lab Analyst

SEP Disaster Recovery and Backup Restore: Best

Implementing Offline Digital Video Storage using XenData Software

Red Hat Storage Server

Deploying a distributed data storage system on the UK National Grid Service using federated SRB

VERITAS Backup Exec 9.0 for Windows Servers

Migration and Building of Data Centers in IBM SoftLayer with the RackWare Management Module

High Performance Computing OpenStack Options. September 22, 2015

How To Encrypt Data On A Network With Cisco Storage Media Encryption (Sme) For Disk And Tape (Smine)

Rapid Data Backup and Restore Using NFS on IBM ProtecTIER TS7620 Deduplication Appliance Express IBM Redbooks Solution Guide

EmulexSecure 8Gb/s HBA Architecture Frequently Asked Questions

owncloud Architecture Overview

Next Generation Backup Solutions

Evaluation of Enterprise Data Protection using SEP Software

FileCloud Security FAQ

MarkLogic Server. Database Replication Guide. MarkLogic 8 February, Copyright 2015 MarkLogic Corporation. All rights reserved.

Gladinet Cloud Backup V3.0 User Guide

EMC Data de-duplication not ONLY for IBM i

Universal Backup Device The Essential Facts of UBD

HP StoreOnce Product Line

Alliance Key Manager Solution Brief

Integrating Red Hat Enterprise Linux 6 with Microsoft Active Directory Presentation

Backup and Recovery Solutions for Exadata. Cor Beumer Storage Sales Specialist Oracle Nederland

Advancements in Storage QoS Management in National Data Storage

Copyright 2011, Storage Strategies Now, Inc. All Rights Reserved.

Stretching A Wolfpack Cluster Of Servers For Disaster Tolerance. Dick Wilkins Program Manager Hewlett-Packard Co. Redmond, WA dick_wilkins@hp.

Cost Effective Backup with Deduplication. Copyright 2009 EMC Corporation. All rights reserved.

Designing a Cloud Storage System

Cloud Storage. Parallels. Performance Benchmark Results. White Paper.

Intro to AWS: Storage Services

Distributed File System Choices: Red Hat Storage, GFS2 & pnfs

Chapter 11: File System Implementation. Operating System Concepts with Java 8 th Edition

CrashPlan Security SECURITY CONTEXT TECHNOLOGY

WOS Cloud. ddn.com. Personal Storage for the Enterprise. DDN Solution Brief

A simple object storage system for web applications Dan Pollack AOL

Secure data storage. André Zúquete Security 1

Complying with PCI Data Security

Nexsan Assureon for Healthcare Introduction

Transcription:

Polish National Data Storage Norbert Meyer, Maciej Brzeźniak, Maciej Stroiński PSNC Workshop on Big Data and Open Data, Brussels. May 7-8, 2014

Data = value => needs protection! Data is value:! Expensive research results! Priceless cultural heritage:! Data needed for organiza9ons / projects to operate Data produchon worldwide (IDC): =! Some of these data need protechon! In Poland: Country: Digital library: Individuals: PB s of data /year 100 s of TB/year 100 s of GB/year

Data archiving/backup is complex! Limited media durability: 5-10 years 5-10 years 10 years? 15-30 years (5000 mount)! Limited technology lifehme IBM 350 (1956) 3,5 hard drive (Rodime, 1986) SSD (1995, M- Systems)! Costs, complexity, lack of know- how

NDS2: use cases 1. Individual user (scien9st, researcher, student): Data to be available, persistent and safe Easy and efficient access to data from various OSs I want transparent safety and security mechanisms I want to share my data and be able to publish them Data storage and access DATA REMOTE STORAGE Data sharing and publicahon DATA SECURED and REPLICATED DATA

NDS2: use cases 2. InsHtuHon, workgroup (digital library, scien9fic project) My data must be available, persistent and safe I need a local working space with simple and efficient access through typical LAN protocols (CIFS, NFS) Local space should be extended by a remote space Local storage and access Remote backup and retrieval DATA CIFS/samba LOCAL STORAGE SFTP REMOTE STORAGE DATA SECURED and REPLICATED DATA

Solution: outsourcing to PLATON project! Added values:! Trusted service provider! CollaboraHon history! Knowledge & experience! Availability & proximity:! Redundant infrastructure! Broadband network to universi9es! and research centres! AddiHonal services! IdP, AAI Data PLATON-U4 service

The infrastructure storage redundancy & high capacity! MulHple sites, geographically distant data centres! Data replicated over the sites! Storage resources: 12,5 PB of tapes; 2 PB of disks

NDS2: problem defini9on 8

NDS2: secure, efficient and easy to use To provide at the same Hme: Data provided on a safety and secure way Efficiency of data storage and access Transparency of safety and security mechanisms Data sharing support Support for data publica9on

Requirements addressed by NDS plaform Features Comments Data availability & persistency Basic security Data sharing within a group Easy and efficient access Safety mechanism transparent & scalable Replica9on, consistency checks Transfer encryp9on, access control at rest, policies (media degaussing) Server- side Linux filesystems mechanisms for access control Access to data through number of protocols: SFTP, WebDAV, Web GUI, GridFTP First replica created by user using a convenient protocol; then replicas created async. using GridFTP for efficiency in WAN

NDS2 a secure and extended NDS NDS and PLATON experience: Replica9on, data persistency etc. OK! EncrypHon and integrity control needed! Manual implementa9on too complicated Exis9ng tools not good enough System shoud beger integrate with user s system (Win, Linux, mobiles ) and ins9tu9on / workgroup environment NDS2 (2011-2013): NaHonal Data Store 2: End- to- end encryphon & integrity control Easy and efficient data exchange Virtual disks for Windows, Linux Appliance for ins9tu9ons Portable GUI client for individuals

NDS2 Features End- to- end security: privacy & integrity Easy access, safery mechanisms transparency Rollback and versioning Easy, efficient and secure data exchange Mobile access Efficient & easy local storage & access + remote backup Comments AES- 256 for data, RSA for key exchange, SHA digests Client- side cryptography provided by easy to use clients: virtual filesystems, Java GUI Server- side versioning + support in clients Symm. and assym. key hierarchy, key exchange mechanisms Android applica9on Appliance for ins9tu9ons

NDS2 cryptography: encryp9on, integrity control and keys management 13

NDS2 cryptography: encryphon, integrity control and keys mgmt (1) Overall concept: Data encrypted with AES- 256 CTR AES - Strong and high performance algorithm for bulk data, resistant to brute force agacks Hardware supported: Intel Westmere and ARMv8 Performance: 1-2,5 GB/s on todays worksta9ons CTR mode enables parallelism Integrity control by SHA- 512: Resistant to collisions and agacks Calculated: User- side (per 64kB logical block) in order to enable users to detect manipula9ons or corrup9on on data or their digest System- side (per file) for replica integrity control

NDS2 cryptography: encryphon, integrity control and keys mgmt (2) Client- side encryphon and integrity control: AES 256 CBC generated per file for data privacy Stored in the file header on the system side Protected with user s private RSA key => User takes care of only 1 pair of keys SHA- 512 digests calculated per logical 64- byte block Stored with each block on the system side Protected by encryphon using files symetric key => User applicahon may access digest informahon using file s AES key file header data chunk 1 data chunk 2 516 Bytes Version (4 Bytes), { symmetric key+ NONCE, header digest } encrypted with RSA 4k 64 kbytes { Data length in this chunk (4 Bytes) SHA512 block digest (64 Bytes) User data (65468 Bytes) } encrypted with AES and file symmetric 64 kbytes { Data length in this chunk (4 Bytes) SHA512 block digest (64 Bytes) User data (65468 Bytes) } encrypted with AES and file symmetric...

NDS2 cryptographic clients: Features & concept: Implementa9on, 16

Clients for NDS2 (1) Windows users CryptoFS 4Windows FS- like access (.net CallbackFS) EncrypHon & digests (.net crypto API) SFTP client (Rebex SFT library) Linux users CryptoFS 4Linux SSHFS extension FS- like access (FUSE/SSHFS) EncrypHon & digests (OpenSSL) SFTP client (Built- into SSHFS) Work- groups Appliance LAN access through CIFS (Samba server) FS- like access (CryptoFS 4 Linux) Admin. interface (php + perl) Local disk storage WAN (SFTP) NDS filesystem (extended with versioning, ACLs) SECURED and REPLICATED DATA

Clients for NDS2 (2) Any plaform Java GUI, CLI and API Browser- like access Drag & dropp EncrypHon & digests (Bouncy Castle) SFTP client (JSCH snp) Metadata search Mobile plaform mmm Android client Browser- like access EncrypHon & digests (Java API) SFTP client (Java API) IntegraHon with Android shell WAN (SFTP) SECURED and REPLICATED DATA

Clients for NDS2 (3) Dropbox- like funchonality Experimental data sync client 4 Windows: Based on CryptoFS4Win components MS Synchronisa9on Framework for synchronisa9on WAN (SFTP) SECURED and REPLICATED DATA

NDS2: appliance concept Use cases: Small ins9tu9on / workgroup shares data using local NAS appliance Data protected against disaster and intrusion: backup and encryp9on Remote space is a backup of local; local is cache of remote The idea: NDS2appliance LAN Local disk space Data access & sharing (CIFS) SMB/CIFS server Backup / restore WAN Users MGMT interface (web) Remote storage/ backup space Data access + encryp2on LDAP/ AcHve Directory server Appliance admin Private cloud Public cloud

NDS in PLATON (3) Sites vs system instances (1) Example instances: PZ1 and WA1 Regional instance Project-dedicated instances

NDS software architecture Overall architecture User Meta- data DB Database Node Access Methods Servers (SSH, HTTPs, WebDAV...) VFS for data and meta- data NDS system logic Access Node Users DB AccounHng & limits DB Replica access methods servers (NFS, GridFTP) Replica2on Storage Node Storage Node FS with data migrahon (HSM) HSM system (NFS) NAS appliance

PLATON s PAS infrastructure: Tape & Disk Storage sites (15+ PB) IBM TS3500 Tape library in Poznan

PLATON s PAS infrastructure: Tape & Disk Storage sites TSM/HSM storage servers Access Node and Database Node servers IBM DS5300 AND DS5100 disk arrays in Poznan 10 Gbit and 1 Gbit switches

Summary Na9onal service as an added value to the network connec9on or independent Base for the Common Data Services Provided for individuals SMEs universi9es Worked out sustainability policy