Software-Defined Data Protection: Low Overhead Policy Compliance at the Storage Layer is Within Reach!
Zsolt István, Soujanya Ponnapalli, Vijay Chidambaram
Abstract
Most modern data processing pipelines run on top of a distributed storage layer, and securing the whole system, and the storage layer in particular, against accidental or malicious misuse is crucial to ensuring compliance to rules and regulations. Enforcing data protection and privacy rules, however, stands at odds with the requirement to achieve higher and higher access bandwidths and processing rates in large data processing pipelines. In this work we describe our proposal for the path forward that reconciles the two goals. We call our approach "Software-Defined Data Protection" (SDP). Its premise is simple, yet powerful: decoupling often changing policies from request-level enforcement allows distributed smart storage nodes to implement the latter at line-rate. Existing and future data protection frameworks can be translated to the same hardware interface which allows storage nodes to offload enforcement efficiently both for company-specific rules and regulations, such as GDPR or CCPA. While SDP is a promising approach, there are several remaining challenges to making this vision reality. As we explain in the paper, overcoming these will require collaboration across several domains, including security, databases and specialized hardware design.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- ShEF: shielded enclaves for cloud FPGAsMark Zhao, Mingyu Gao, Christos KozyrakisASPLOS 2022 · 53 citations
- Retrofitting GDPR Compliance onto Legacy DatabasesArchita Agarwal, Marilyn George, Aaron R. Jeyaraj, Malte SchwarzkopfVLDB 2022 · 16 citations
- K9db: Privacy-Compliant Storage For Web Applications By ConstructionKinan Dak Albab, Ishan Sharma, Justus Adam, Benjamin Kilimnik et al.OSDI 2023 · 7 citations
- Secure and Policy-Compliant Query Processing on Heterogeneous Computational Storage ArchitecturesHarshavardhan Unnibhavi, David Cerdeira, Antonio Barbalace, Nuno Santos et al.SIGMOD 2022 · 5 citations
- RuleKeeper: GDPR-Aware Personal Data Compliance for Web FrameworksMafalda Ferreira, Tiago Brito, José Fragoso Santos, Nuno SantosS&P 2023
Builds on3
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic et al.EuroSys 2020 · 381 citations
- Understanding and Benchmarking the Impact of GDPR on Database SystemsSupreeth Shastri, Vinay Banakar, Melissa Wasserman, Arun Kumar et al.VLDB 2020 · 82 citations
- Evanesco: Architectural Support for Efficient Data Sanitization in Modern Flash-Based Storage SystemsMyungsuk Kim, Jisung Park, Genhee Cho, Yoona Kim et al.ASPLOS 2020 · 24 citations
Related papers
- PrivGuard: Privacy Regulation Compliance Made EasierLun Wang, Usmann Khan, Joseph P. Near, Qi Pang et al.USENIX Security 2022
- PAIO: General, Portable I/O Optimizations With Minor Application ModificationsRicardo Macedo, Yusuke Tanimura, Jason Haga, Vijay Chidambaram et al.FAST 2022
- Encoding Privacy: Sociotechnical Dynamics of Data Protection Compliance WorkRohan GroverCHI 2024 · 8 citations
- Sieve: A Middleware Approach to Scalable Access Control for Database Management SystemsPrimal Pappachan, Roberto Yus, Sharad Mehrotra, Johann-Christoph FreytagVLDB 2020
- Data Guard: A Fine-Grained Purpose-Based Access Control System for Large Data WarehousesKhai Tran, Sudarshan Vasudevan, Pratham Desai, Alex Gorelik et al.ICDE 2026
