An implementation of a secure version of NFS including RBAC

Paul Ashley, Bradley Broom, Mark Vandenwauver

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

The NFS protocol provides transparent remote access to shared file systems across networks. It is very popular particularly in Unix networks where it is probably the most common distributed file system technology. NFS however is rarely used outside closed protected networks, because its security is notoriously weak. In 1998 Sun Microsystems released what is considered the first attempt at providing comprehensive security to NFS: a security flavour called RPCSEC_GSS based on Kerberos V5 and the GSS-API. The main benefit of this version over previous versions is that for the first time each NFS file access call could be protected. This paper outlines our efforts to secure NFS producing a security solution with even greater functionality. The major new functionality is that users may optionally use an access control system based on role based access control (RBAC). RBAC allows users to log in, be provided with a role, and use this to transparently access their remote files through secure NFS. There are also other advantages provided, for example security for the mount protocol and the option of public-key technology for authentication and key distribution. NFS has been secured with SESAME V4 and the practicality and performance of this mechanism has been demonstrated by modifying the Linux kernel and NFS utilities.

Original languageEnglish (US)
Title of host publicationInformation Security and Privacy - 4th Australasian Conference, ACISP 1999, Proceedings
EditorsJosef Pieprzyk, Rei Safavi-Naini, Jennifer Seberry
PublisherSpringer Verlag
Pages213-227
Number of pages15
ISBN (Print)3540657568, 9783540657569
DOIs
StatePublished - 1999
Externally publishedYes
Event4th Australasian Conference on Information Security and Privacy, ACISP 1999 - Wollongong, Australia
Duration: Apr 7 1999Apr 9 1999

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume1587
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Other

Other4th Australasian Conference on Information Security and Privacy, ACISP 1999
Country/TerritoryAustralia
CityWollongong
Period4/7/994/9/99

ASJC Scopus subject areas

  • Theoretical Computer Science
  • General Computer Science

Fingerprint

Dive into the research topics of 'An implementation of a secure version of NFS including RBAC'. Together they form a unique fingerprint.

Cite this