EGEON: Software-Defined Data Protection for Object Storage

06/27/2022
by   Raul Saiz-Laudo, et al.
0

With the growth in popularity of cloud computing, object storage systems (e.g., Amazon S3, OpenStack Swift, Ceph) have gained momentum for their relatively low per-GB costs and high availability. However, as increasingly more sensitive data is being accrued, the need to natively integrate privacy controls into the storage is growing in relevance. Today, due to the poor object storage interface, privacy controls are enforced by data curators with full access to data in the clear. This motivates the need for a new approach to data privacy that can provide strong assurance and control to data owners. To fulfill this need, this paper presents EGEON, a novel software-defined data protection framework for object storage. EGEON enables users to declaratively set privacy policies on how their data can be shared. In the privacy policies, the users can build complex data protection services through the composition of data transformations, which are invoked inline by EGEON upon a read request. As a result, data owners can trivially display multiple views from the same data piece, and modify these views by only updating the policies. And all without restructuring the internals of the underlying object storage system. The EGEON prototype has been built atop OpenStack Swift. Evaluation results shows promise in developing data protection services with little overhead directly into the object store. Further, depending on the amount of data filtered out in the transformed views, end-to-end latency can be low due to the savings in network communication.

READ FULL TEXT
research
07/08/2021

Zeph: Cryptographic Enforcement of End-to-End Data Privacy

As increasingly more sensitive data is being collected to gain valuable ...
research
08/11/2020

Towards Software-Defined Data Protection: GDPR Compliance at the Storage Layer is Within Reach

Enforcing data protection and privacy rules within large data processing...
research
06/29/2018

Complying with Data Handling Requirements in Cloud Storage Systems

In past years, cloud storage systems saw an enormous rise in usage. Howe...
research
11/19/2019

Audita: A Blockchain-based Auditing Framework for Off-chain Storage

The cloud changed the way we manage and store data. Today, cloud storage...
research
04/05/2018

A Fast Fragmentation Algorithm For Data Protection In a Multi-Cloud Environment

Data fragmentation and dispersal over multiple clouds is a way of data p...
research
06/25/2020

Privacy at Facebook Scale

Most organizations today collect data across every facet of their busine...
research
06/07/2021

PAIO: A Software-Defined Storage Data Plane Framework

We propose PAIO, the first general-purpose framework that enables system...

Please sign up or login with your details

Forgot password? Click here to reset