In past years, cloud storage systems saw an enormous rise in usage. However, despite their popularity and importance as underlying infrastructure for more complex cloud services, today's cloud storage systems do not account for compliance with regulatory, organizational, or contractual data handling requirements by design. Since legislation increasingly responds to rising data protection and privacy concerns, complying with data handling requirements becomes a crucial property for cloud storage systems. We present PRADA, a practical approach to account for compliance with data handling requirements in key-value based cloud storage systems. To achieve this goal, PRADA introduces a transparent data handling layer, which empowers clients to request specific data handling requirements and enables operators of cloud storage systems to comply with them. We implement PRADA on top of the distributed database Cassandra and show in our evaluation that complying with data handling requirements in cloud storage systems is practical in real-world cloud deployments as used for microblogging, data sharing in the Internet of Things, and distributed email storage.
翻译:过去几年来,云储存系统的使用量大幅上升,然而,尽管云储存系统作为更复杂的云服务的基础基础设施受到欢迎且十分重要,但今天的云储存系统并没有按设计遵守监管、组织或合同数据处理要求;由于立法日益响应数据保护和隐私方面的越来越多的关切,遵守数据处理要求成为云储存系统的重要财产;我们提出了“云储存系统”这一实用方法,用于核算关键价值云储存系统数据处理要求的遵守情况;为实现这一目标,PRADA引入了一个透明的数据处理层,使客户能够要求具体的数据处理要求,并使云储存系统的操作者能够遵守这些规定;我们在分布的数据库卡桑德拉上实施了“云储存系统”的“数据处理要求”,并在我们的评价中表明,在实际部署云储存系统的数据处理要求是实用的,用于微博、在信息互联网上分享数据以及分发电子邮件储存。