Building Deletion-Compliant Data Systems

Building Deletion-Compliant Data Systems
复制标题

DOI:
--
复制
发表时间:
2022
期刊:
IEEE Data Eng. Bull.
影响因子:
--
通讯作者:
Manos Athanassoulis;Subhadeep Sarkar;Tarikul Islam Papon;Zichen Zhu;Dimitris Staratzis
Manos Athanassoulis;Subhadeep Sarkar;Tarikul Islam Papon;Zichen Zhu;Dimitris Staratzis
中科院分区:
其他
文献类型:
--
作者:
Manos Athanassoulis;Subhadeep Sarkar;Tarikul Islam Papon;Zichen Zhu;Dimitris Staratzis

文献摘要

相似文献

大多数现代数据系统的设计都考虑到两个目标——快速摄取和低延迟查询处理。第一个目标导致了大量采用异地范例的写优化数据存储的开发。由于其写优化设计,异地数据系统通过失效逻辑执行删除,并保留无效数据任意长时间。然而,由于最近颁布了新的数据隐私法规,及时删除用户数据的要求已成为核心。被遗忘权(在欧盟的 GDPR 中)、删除权(在加利福尼亚州的 CCPA 和 CPRA 中)或删除权(在弗吉尼亚州的 VCDPA 中)要求服务提供商在预设的时间内持续删除用户的数据。然而,异地数据系统中的逻辑删除并不能保证及时和持久的删除,并且尝试使用现有工具强制执行会导致性能不佳并增加运营成本。在本文中,我们提出了一个从整体角度构建删除兼容数据系统的新框架。我们分析新法规和新政策衍生的要求,提出数据管理应用层和系统层的改变。我们概述了需要支持的新类型的删除请求、能够请求及时持久数据删除所需的查询语言修改以及实现及时和持久删除所需的系统级更改。拟议的删除合规性框架为新型数据系统奠定了基础,该系统可以为用户数据隐私提供系统级保证。我们展示了涵盖框架所有层的最新结果:需求和应用程序层针对任何数据库系统,而系统层讨论则针对异地系统。最后,我们讨论了构建删除兼容数据系统的后续步骤和开放挑战。
Most modern data systems have been designed with two goals in mind – fast ingestion and low-latency query processing. The first goal has led to the development of a plethora of write-optimized data stores that employ the out-of-place paradigm. Due to their write-optimized design, out-of-place data systems perform deletes logically via invalidation, and retain the invalid data for arbitrarily long. However, due to the recent enactment of new data privacy regulations, the requirement of timely deletion of user data has become central. The right to be forgotten (in EU’s GDPR), right to delete (in California’s CCPA and CPRA), or deletion right (in Virginia’s VCDPA) mandates that service providers persistently delete a user’s data within a pre-set time duration. Logical deletion in out-of-place data systems, however, does not offer guarantees for timely and persistent deletion, and attempting to enforce it using existing tools leads to poor performance and increased operational costs. In this paper, we present a new framework for building deletion-compliant data systems from a holistic perspective. We analyze the new regulations and the requirements derived from the new policies, and we propose changes in the application and the system layer of data management. We outline the new types of deletion requests that need to be supported, the query language modifications needed to be able to request for timely persistent data deletion, and the system-level changes needed to realize timely and persistent deletes. The proposed framework for deletion compliance lays the groundwork for a new class of data systems that can offer system-level guarantees for user data privacy. We present recent results spanning all layers of the framework: the requirements and the application layer target any database system, while the system layer discussion is geared towards out-of-place systems. Finally, we conclude with a discussion on next steps and open challenges on building deletion-compliant data systems.