Trustworthy Migration and Retrieval of Regulatory Compliant Records

Soumyadeb Mitra, M. Winslett, W. Hsu, Xiaonan Ma
{"title":"Trustworthy Migration and Retrieval of Regulatory Compliant Records","authors":"Soumyadeb Mitra, M. Winslett, W. Hsu, Xiaonan Ma","doi":"10.1109/MSST.2007.35","DOIUrl":null,"url":null,"abstract":"Compliance storage servers are designed to meet organizational needs for trustworthy records retention, largely mandated by recent legislations such as HIPAA, SEC Rule 17a, and the Sarbanes-Oxley Act. These devices export a file-system-level interface, and enforce write-once read- many (WORM) semantics for file access. Compliance storage protects records from alteration, as long as they remain on the same storage server. However, the decades-long records retention requirements of recent legislation mean that a compliance storage server will often be obsolete long before the documents it contains can be destroyed. Unfortunately, records will be vulnerable to change during migration to a new server. Records are also vulnerable during retrieval, when they are taken off the server and \"migrated\" to the person or organization who needs them. In this paper, we propose techniques for trustworthy document migration and retrieval, by enhancing the storage servers with the capability to sign their files and directories. The proposed techniques can be used to verify that a migration was carried out properly, even across multiple migrations, deletions of expired documents, and changes in the content and structure of migrated directories. In our approach, file writers incur no performance penalty, which is important since compliance workloads are write-intensive. Migration incurs a reasonable 5-10% space overhead and requires 24 msec processing time per file. The result of the migration can be verified at a rate of 24 msec per file by a trustworthy auditor (or ordinary user), who can then generate a certificate attesting to the correctness of the migration.","PeriodicalId":109619,"journal":{"name":"24th IEEE Conference on Mass Storage Systems and Technologies (MSST 2007)","volume":"231 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-09-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"24th IEEE Conference on Mass Storage Systems and Technologies (MSST 2007)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MSST.2007.35","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

Compliance storage servers are designed to meet organizational needs for trustworthy records retention, largely mandated by recent legislations such as HIPAA, SEC Rule 17a, and the Sarbanes-Oxley Act. These devices export a file-system-level interface, and enforce write-once read- many (WORM) semantics for file access. Compliance storage protects records from alteration, as long as they remain on the same storage server. However, the decades-long records retention requirements of recent legislation mean that a compliance storage server will often be obsolete long before the documents it contains can be destroyed. Unfortunately, records will be vulnerable to change during migration to a new server. Records are also vulnerable during retrieval, when they are taken off the server and "migrated" to the person or organization who needs them. In this paper, we propose techniques for trustworthy document migration and retrieval, by enhancing the storage servers with the capability to sign their files and directories. The proposed techniques can be used to verify that a migration was carried out properly, even across multiple migrations, deletions of expired documents, and changes in the content and structure of migrated directories. In our approach, file writers incur no performance penalty, which is important since compliance workloads are write-intensive. Migration incurs a reasonable 5-10% space overhead and requires 24 msec processing time per file. The result of the migration can be verified at a rate of 24 msec per file by a trustworthy auditor (or ordinary user), who can then generate a certificate attesting to the correctness of the migration.
法规遵从记录的可信迁移和检索
遵从性存储服务器旨在满足组织对可信记录保留的需求,这在很大程度上是由最近的立法(如HIPAA、SEC Rule 17a和Sarbanes-Oxley Act)强制要求的。这些设备导出文件系统级接口,并对文件访问强制执行写一次读多次(WORM)语义。遵从性存储保护记录免受更改,只要它们保持在相同的存储服务器上。然而,最近立法中长达数十年的记录保留要求意味着遵从性存储服务器通常在其包含的文件被销毁之前就已经过时了。不幸的是,在迁移到新服务器期间,记录很容易发生更改。在检索过程中,当记录从服务器中取出并“迁移”到需要它们的个人或组织时,它们也很容易受到攻击。在本文中,我们通过增强存储服务器对其文件和目录签名的能力,提出了可信文档迁移和检索技术。建议的技术可用于验证迁移是否正确执行,甚至跨多个迁移、删除过期文档以及更改已迁移目录的内容和结构。在我们的方法中,文件写入器不会产生性能损失,这一点很重要,因为遵从性工作负载是写密集型的。迁移会产生合理的5-10%的空间开销,并且每个文件需要24毫秒的处理时间。迁移的结果可以由值得信赖的审计员(或普通用户)以每个文件24毫秒的速度进行验证,然后审计员可以生成证明迁移正确性的证书。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信