SHANDONG SCIENCE ›› 2014, Vol. 27 ›› Issue (5): 33-41.doi: 10.3976/j.issn.1002-4026.2014.05.007

• Article • Previous Articles     Next Articles

PKI based HDFS authentication and secure transmission mechanism

LI Yan-gai, ZHAO Hua-wei   

  1. 1. School of Computer Science and Technology, Shandong University of Finance and Economics, Jinan 250014,China; 2. Shandong Zhongfu Information Industry Co.,Ltd., Jinan 250101, China
  • Received:2014-05-21 Online:2014-10-20 Published:2014-10-20

Abstract: We detailedly analyze existing Kerberos scheme to solve the authentication and secure transmission in the process of file service of Hadoop Distributed File System(HDFS), a core subproject of Hadoop. We then generalize the negatives of its security and efficiency. We further apply PKI based digital certificate authentication and digital envelop based AES symmetric encryption to the security mechanism of HDFS. Analysis shows that the approach can provide a safer and more efficient solution for HDFS service, as compared with Kerberos.

Key words: Kerberos, PKI, Hadoop, security of HDFS

CLC Number: 

  • TP393.08