• DocumentCode
    2844919
  • Title

    Managing data retention policies at scale

  • Author

    Li, Jun ; Singhal, Sharad ; Swaminathan, Ram ; Karp, Alan H.

  • Author_Institution
    Hewlett-Packard Labs., Palo Alto, CA, USA
  • fYear
    2011
  • fDate
    23-27 May 2011
  • Firstpage
    57
  • Lastpage
    64
  • Abstract
    Compliance with regulatory policies on data remains a key hurdle to cloud computing. Policies such as EU privacy, HIPAA, and PCI-DSS place requirements on data availability, integrity, migration, retention, and access, among many others. This paper proposes a policy management service that offers scalable management of data retention policies attached to data objects stored in a cloud environment. The management service includes a highly available and secure encryption key store to manage the encryption keys of data objects. By deleting the encryption key at a specified retention time associated with the data object, we effectively delete the data object and its copies stored in online and offline environments. To achieve scalability, our service uses Hadoop MapReduce to perform parallel management tasks, such as data encryption and decryption, key distribution and retention policy enforcement. A prototype deployed in a 16-machine Linux cluster currently supports 56 MB/sec for encryption, 76 MB/sec for decryption, 31,000 retention policies/sec read and 15,000 retention policies/sec write.
  • Keywords
    cloud computing; cryptography; data integrity; data privacy; EU privacy; HIPAA; Hadoop MapReduce; Linux cluster; PCI-DSS; cloud computing; data access; data availability; data decryption; data encryption; data integrity; data migration; data retention policy management; encryption keys management; key distribution; management service; parallel management tasks; regulatory policy; retention policy enforcement; Cryptography; Decision support systems; Engines; Google; Laboratories; Protocols; cloud service; data retention; encryption key store; large-scale policy management; regulatory compliance;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Integrated Network Management (IM), 2011 IFIP/IEEE International Symposium on
  • Conference_Location
    Dublin
  • Print_ISBN
    978-1-4244-9219-0
  • Electronic_ISBN
    978-1-4244-9220-6
  • Type

    conf

  • DOI
    10.1109/INM.2011.5990674
  • Filename
    5990674