Software-Defined Data Protection: Low Overhead Policy Compliance at the Storage Layer is Within Reach!
Zsolt István, Soujanya Ponnapalli, Vijay Chidambaram
摘要
Most modern data processing pipelines run on top of a distributed storage layer, and securing the whole system, and the storage layer in particular, against accidental or malicious misuse is crucial to ensuring compliance to rules and regulations. Enforcing data protection and privacy rules, however, stands at odds with the requirement to achieve higher and higher access bandwidths and processing rates in large data processing pipelines. In this work we describe our proposal for the path forward that reconciles the two goals. We call our approach "Software-Defined Data Protection" (SDP). Its premise is simple, yet powerful: decoupling often changing policies from request-level enforcement allows distributed smart storage nodes to implement the latter at line-rate. Existing and future data protection frameworks can be translated to the same hardware interface which allows storage nodes to offload enforcement efficiently both for company-specific rules and regulations, such as GDPR or CCPA. While SDP is a promising approach, there are several remaining challenges to making this vision reality. As we explain in the paper, overcoming these will require collaboration across several domains, including security, databases and specialized hardware design.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- ShEF: shielded enclaves for cloud FPGAsMark Zhao, Mingyu Gao, Christos KozyrakisASPLOS 2022 · 被引用 53 次
- Retrofitting GDPR Compliance onto Legacy DatabasesArchita Agarwal, Marilyn George, Aaron R. Jeyaraj, Malte SchwarzkopfVLDB 2022 · 被引用 16 次
- K9db: Privacy-Compliant Storage For Web Applications By ConstructionKinan Dak Albab, Ishan Sharma, Justus Adam, Benjamin Kilimnik 等OSDI 2023 · 被引用 7 次
- Secure and Policy-Compliant Query Processing on Heterogeneous Computational Storage ArchitecturesHarshavardhan Unnibhavi, David Cerdeira, Antonio Barbalace, Nuno Santos 等SIGMOD 2022 · 被引用 5 次
- RuleKeeper: GDPR-Aware Personal Data Compliance for Web FrameworksMafalda Ferreira, Tiago Brito, José Fragoso Santos, Nuno SantosS&P 2023
它引用的顶会 Paper3
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic 等EuroSys 2020 · 被引用 381 次
- Understanding and Benchmarking the Impact of GDPR on Database SystemsSupreeth Shastri, Vinay Banakar, Melissa Wasserman, Arun Kumar 等VLDB 2020 · 被引用 82 次
- Evanesco: Architectural Support for Efficient Data Sanitization in Modern Flash-Based Storage SystemsMyungsuk Kim, Jisung Park, Genhee Cho, Yoona Kim 等ASPLOS 2020 · 被引用 24 次
相关 Paper
- PrivGuard: Privacy Regulation Compliance Made EasierLun Wang, Usmann Khan, Joseph P. Near, Qi Pang 等USENIX Security 2022
- PAIO: General, Portable I/O Optimizations With Minor Application ModificationsRicardo Macedo, Yusuke Tanimura, Jason Haga, Vijay Chidambaram 等FAST 2022
- Encoding Privacy: Sociotechnical Dynamics of Data Protection Compliance WorkRohan GroverCHI 2024 · 被引用 8 次
- Sieve: A Middleware Approach to Scalable Access Control for Database Management SystemsPrimal Pappachan, Roberto Yus, Sharad Mehrotra, Johann-Christoph FreytagVLDB 2020
- Data Guard: A Fine-Grained Purpose-Based Access Control System for Large Data WarehousesKhai Tran, Sudarshan Vasudevan, Pratham Desai, Alex Gorelik 等ICDE 2026
