loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
First International IEEE Security in Storage Workshop
Performance Study of Software-Based iSCSI Security
Greenbelt, Maryland
December 11-December 11
ISBN: 0-7695-1888-5
Shuang-Yi Tang, University of Minnesota
Ying-Ping Lu, University of Minnesota
David H.C. Du, University of Minnesota
In this paper, we study possible iSCSI security schemes that satisfy different security requirements. To evaluate the performance of different security schemes, we conduct performance experiments using a software- based iSCSI implementation with proper security extensions. In data encryption schemes, we consider two alternatives, IP Security Protocol (IPSec) and Secure Socket Layer (SSL), and compare the resulting iSCSI performances with these two schemes. We find that the software-based iSCSI implementation offers reasonable throughput with a 2 GHz CPU at the network speed of 100Mbps; however, with a 1 GHz CPU, the software implementation is not capable of providing sufficient throughput with triple-DES encrypted storage data. In addition, we also find that IPSec ESP scheme has better performance when the requested data size is small, compared to SSL. Given that both performance and security are critical issues in the deployment of iSCSI, it is important to understand the tradeoffs between them. We believe that this study sheds some helpful light on this understanding.
Citation:
Shuang-Yi Tang, Ying-Ping Lu, David H.C. Du, "Performance Study of Software-Based iSCSI Security," sisw, pp.70, First International IEEE Security in Storage Workshop, 2002
Usage of this product signifies your acceptance of the Terms of Use.