SHIELD: Encrypting Persistent Data of LSM-KVS from Monolithic to Disaggregated Storage
Viraj Thakkar, Dongha Kim, Yingchun Lai, Hokeun Kim, Zhichao Cao
Abstract
Log-Structured Merge-tree-based Key-Value Stores (LSM-KVS) are widely used to support modern, high-performance, data-intensive applications. In recent years, with the trend of deploying and optimizing LSM-KVS from monolith to Disaggregated Storage (DS) setups, the confidentiality of LSM-KVS persistent data (e.g., WAL and SST files) is vulnerable to unauthorized access from insiders and external attackers and must be protected using encryption. Existing solutions lack a high-performance design for encryption in LSM-KVS, often focus on in-memory data protection with overheads of 3.4-32.5x, and lack the scalability and flexibility considerations required in DS deployments. This paper proposes two novel designs to address the challenges of providing robust security for persistent components of LSM-KVS while maintaining high performance in both monolith and DS deployments - a simple and effective instance-level design suitable for monolithic LSM-KVS deployments, and SHIELD, a design that embeds encryption into LSM-KVS components for minimal overhead in both monolithic and DS deployment. We achieve our objective through three contributions: (1) A fine-grained integration of encryption into LSM-KVS write path to minimize performance overhead from exposure-limiting practices like using unique encryption keys per file and regularly re-encrypting using new encryption keys during compaction, (2) Mitigating performance degradation caused by recurring encryption of Write-Ahead Log (WAL) writes by using a buffering solution and (3) Extending confidentiality guarantees to DS by designing a metadata-enabled encryption-key-sharing mechanism and a secure local cache for high scalability and flexibility. We implement both designs on RocksDB, evaluating them in monolithic and DS setups while showcasing an overhead of 0-32% for the instance-level design and 0-36% for SHIELD.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 37042299-ef3b-49e0-841d-7c876d5a1158Cited by top-tier papers1
Ask how each one uses itBuilds on9
- EnclaveDB: A Secure Database Using SGXChristian Priebe, Kapil Vaswani, Manuel CostaS&P 2018 · 329 citations
- Facebook's Tectonic Filesystem: Efficiency from ExascaleSatadru Pan, Theano Stavrinos, Yunqiao Zhang, Atul Sikaria et al.FAST 2021 · 110 citations
- Hailstorm: Disaggregated Compute and Storage for Distributed LSM-based DatabasesLaurent Bindschaedler, Ashvin Goel, Willy ZwaenepoelASPLOS 2020 · 51 citations
- Nova-LSM: A Distributed, Component-based LSM-tree Key-value StoreHaoyu Huang, Shahram GhandeharizadehSIGMOD 2021 · 47 citations
- Avocado: A Secure In-Memory Distributed Storage SystemMaurice Bailleu, Dimitra Giantsidi, Vasilis Gavrielatos, Do Le Quoc et al.USENIX ATC 2021 · 39 citations
Related papers
- O3-LSM: Maximizing Disaggregated LSM Write Performance via Three-Layer OffloadingQi Lin, Gangqi Huang, Te Guo, Chang Guo et al.SIGMOD 2026 · 2 citations
- CaaS-LSM: Compaction-as-a-Service for LSM-based Key-Value Stores in Storage Disaggregated InfrastructureQiaolin Yu, Chang Guo, Jay Zhuang, Viraj Thakkar et al.SIGMOD 2024 · 18 citations
- Terark-DS: A High-Performance and Storage-Efficient Key-Value Separation Storage Engine on Disaggregated StorageJianshun Zhang, Xun Deng, Fang Wang, Jiaxin Ou et al.VLDB 2026
- PartitionKV: Redesigning LSM-tree KV Stores on NVMs with Adaptive Partitioning for Reducing Write Stalls and AmplificationXingye Huang, Jinyu Wu, Xiaofang Xia, Jiangtao Cui et al.SIGMOD 2026
- ArceKV: Towards Workload-driven LSM-compactions for Key-Value Store Under Dynamic WorkloadsJunfeng Liu, Haoxuan Xie, Siqiang LuoVLDB 2026
