Skip to main content

Securing sensitive info Xerox way


How can Hadoop help to address the challenge of securing sensitive information in a document and limit it to your private cloud? If you want to know how the amazing guys at Xerox have proposed novel architecture to this business problem, then read on.

Since many documents and applications such as electronic medical records (EMR), tax forms, surveys, claims may contain both sensitive private as well as public information, there needs to be a way to protect private and still be able to distribute public info from the same document.

In the architecture approach invented by Shanmuga-nathan Gnanasambandam, Naveen Sharma, Wendell Lewis Kibler (Xerox), firstly, a processor executes to determine document structure from interconnected documents and intelligently indicate “specific information, passages, and/or components of the document as sensitive or insensitive information”. The private information is stored as a file along with meta data on internal cloud storage while the public information is stored as a public file on the external cloud storage like Amazon.

Private and public files may be stored in a replicated fashion in a distributed file system (like HDFS) where a file may be replicated and/or split into a plurality of pieces. “Each piece or replica differs slightly from the others in that each piece or replica includes a bit pattern different from the other (i.e., each replica is not identical byte-for-byte to any other replica)”.



The team goes one step further and once the replicas are stored, the replication process of Hadoop kicks in to store one or more replicas relatively close to the point of consumption and one or more replicas one or more hops away from the point of consumption. “As a result, the farther a particular replicated file is from the point of consumption, the larger the number of replicated files to decode or crack and the longer the encryption key”.

When a user needs to access the entire document, the client program may access and decrypt private file from private cloud along with public file from public cloud, merges them to show one consolidated document view. Hadoop here is architected to compute and store documents in accordance with a multi split/replica approach enabling the unique design.

Comments

Popular posts from this blog

Beyond NSA, the intelligence community has a big technology footprint

While all through the past few days the focus has been on NSA activities, the discussion has often veered around the technologies and products used by NSA. At the same time, a side discussion topic has been the larger technical ecosystem of intelligence units. CIA has been one of the more prolific users of Information Technology by its own admission. To that extent, CIA spinned off a venture capital firm In-Q-Tel in 1999 to invest in focused sector companies. Per Helen Coster of Fortune Magazine, In-Q-Tel (IQT) has been named “after the gadget-toting James Bond character Q”.
In-Q-Tel states on its website that “We design our strategic investments to accelerate product development and delivery for this ready-soon innovation, and specifically to help companies add capabilities needed by our customers in the Intelligence Community”. To that effect, it has made over 200 investments in early stage companies for propping up products. Being a not-for-profit group, unlike Private Venture capi…

Data deduplication tactics with HDFS and MapReduce

As the amount of data continues to grow exponentially, there has been increased focus on stored data reduction methods. Data compression, single instance store and data deduplication are among the common techniques employed for stored data reduction.
Deduplication often refers to elimination of redundant subfiles (also known as chunks, blocks, or extents). Unlike compression, data is not changed and eliminates storage capacity for identical data. Data deduplication offers significant advantage in terms of reduction in storage, network bandwidth and promises increased scalability.
From a simplistic use case perspective, we can see application in removing duplicates in Call Detail Record (CDR) for a Telecom carrier. Similarly, we may apply the technique to optimize on network traffic carrying the same data packets.
Some of the common methods for data deduplication in storage architecture include hashing, binary comparison and delta differencing. In this post, we focus on how MapReduce and…

Top Big Data Influencers of 2015

2015 was an exciting year for big data and hadoop ecosystem. We saw hadoop becoming an essential part of data management strategy of almost all major enterprise organizations. There is cut throat competition among IT vendors now to help realize the vision of data hub, data lake and data warehouse with Hadoop and Spark.
As part of its annual assessment of big data and hadoop ecosystem, HadoopSphere publishes a list of top big data influencers each year. The list is derived based on a scientific methodology which involves assessing various parameters in each category of influencers. HadoopSphere Top Big Data Influencers list reflects the people, products, organizations and portals that exercised the most influence on big data and ecosystem in a particular year. The influencers have been listed in the following categories:

AnalystsSocial MediaOnline MediaProductsTechiesCoachThought LeadersClick here to read the methodology used.

Analysts:Doug HenschenIt might have been hard to miss Doug…