Software-Defined Data Protection: Low Overhead Policy Compliance at the Storage Layer is Within Reach!

Zsolt István, Soujanya Ponnapalli, Vijay Chidambaram

    Publikation: Artikel i tidsskrift og konference artikel i tidsskriftTidsskriftartikelForskningpeer review

    Abstract

    Most modern data processing pipelines run on top of a distributed
    storage layer, and securing the whole system, and the storage layer in particular, against accidental or malicious misuse is crucial to ensuring compliance to rules and regulations. Enforcing data protection and privacy rules, however, stands at odds with the requirement to achieve higher and higher access bandwidths and processing rates in large data processing pipelines.
    In this work we describe our proposal for the path forward
    that reconciles the two goals. We call our approach “Software-
    Defined Data Protection” (SDP). Its premise is simple, yet powerful:
    decoupling often changing policies from request-level enforcement allows distributed smart storage nodes to implement the latter at line-rate. Existing and future data protection frameworks can be translated to the same hardware interface which allows storage nodes to offload enforcement efficiently both for company-specific rules and regulations, such as GDPR or CCPA.
    While SDP is a promising approach, there are several remaining
    challenges to making this vision reality. As we explain in the paper, overcoming these will require collaboration across several domains, including security, databases and specialized hardware design.
    OriginalsprogEngelsk
    TidsskriftProceedings of the VLDB Endowment
    Vol/bind14
    Udgave nummer7
    Sider (fra-til)1167-1174
    ISSN2150-8097
    DOI
    StatusUdgivet - 2021

    Emneord

    • Software-Defined Data Protection
    • Distributed storage
    • Data privacy
    • Access control
    • Regulatory compliance

    Fingeraftryk

    Dyk ned i forskningsemnerne om 'Software-Defined Data Protection: Low Overhead Policy Compliance at the Storage Layer is Within Reach!'. Sammen danner de et unikt fingeraftryk.

    Citationsformater