Raft-Consistent Metadata with GPU-Accelerated Encryption for Secure HDFS
Abstract
In today’s cloud computing environments, large-scale data infrastructures like Hadoop are facing severe challenges in providing efficient and secure static storage; these challenges stem from limitations in single algorithm encryption schemes as well as metadata management instability. This paper proposes a co-designed architecture demonstrating that metadata consistency and high-throughput encryption can be achieved simultaneously without performance trade-offs. Our approach integrates two components: (1) a Raft-consistent metadata service (RCMS) that replaces the single-point-of-failure NameNode with distributed consensus-based replication. Empirical evaluation shows that RCMS has a metadata fail-over latency of 1.35(+-0.42) seconds - an improvement of 78 times over ZooKeeper-based HA (105(+-28) seconds). Such fast recovery is essential for metadata-sensitive applications such as real-time analytics, streaming applications, and interactive SQL engines. Concomitantly, GHEM provides the encryption throughput of 935 MB/s, which is 51% uplift from CPU-based HDFS-TDE’s throughput of 620 MB/s. 8.1 times faster compared to 10 GB files. The key to achieving this architecture is that RCMS and GHEM are executed in non-overlapping critical paths and that metadata transactions and data encryption are performed in parallel with the network I/O, with a total overhead of less than 1%, given all together. This co-design confronts this entrenched notion that strong consistency forces performance compromises. Experimental validation for a four-node prototype cluster validates both the fast fail-over of metadata and the high-throughput encryption facilities. Finally, the proposed framework is easily extendable to various types of distributed storage systems, including Ceph, Cassandra, and cloud object storage, which makes this framework a solid foundation for building secure, consistent, and high-performance data storage solutions.
Keywords
Ethical Statement
Thanks
References
- T. K. Vashishth, V. Sharma, B. Kumar, and K. K. Sharma, “Cloud-based data management for behavior analytics in business and finance sectors,” in Data-Driven Modeling and Predictive Analytics in Business and Finance. Boca Raton, FL, USA: Auerbach Publications, 2024, pp. 133–155.
- P. Murugesan and V. A. Kakumanu, “Hadoop-based secure storage solution for big data in cloud computing environment using elliptic curve Diffie–Hellman algorithm,” in Proc. 2024 Int. Conf. Data Sci. Netw. Secur. (ICDSNS), 2024, pp. 1–6.
- S. Guan, C. Zhang, Y. Wang, and W. Liu, “Hadoop-based secure storage solution for big data in cloud computing environment,” Digit. Commun. Netw., vol. 10, no. 1, pp. 227–236, 2024.
- H. A. Alameen and F. Rabee, “Blockchain-based metadata management in distributed file systems,” Mesopotamian J. Cybersecur., vol. 5, no. 2, pp. 349–360, 2025.
- S. Almasi and G. Pratx, “Cloud computing for big data,” in Big Data in Radiation Oncology. Boca Raton, FL, USA: CRC Press, 2019, pp. 61–78.
- T. Ahn, M. Choi, H. T. Lee, J. Paek, S. Cho, and Y. Son, “A survey on metadata management in file systems,” in Proc. 2024 15th Int. Conf. Inf. Commun. Technol. Convergence (ICTC), 2024, pp. 442–447.
- V. Lukaj, A. Catalfamo, F. Martella, M. Fazio, M. Villari, and A. Celesti, “A NoSQL DBMS transparent data encryption approach for cloud/edge continuum,” in Proc. 2023 IEEE Symp. Comput. Commun. (ISCC), 2023, pp. 430–435.
- F. M. Awaysheh, “From the cloud to the edge towards a distributed and lightweight secure big data pipeline for IoT applications,” in Trust, Security and Privacy for Big Data. Boca Raton, FL, USA: CRC Press, pp. 50–68, 2022.
Details
Primary Language
English
Subjects
Cloud Computing Security
Journal Section
Research Article
Authors
Publication Date
September 30, 2026
Submission Date
August 2, 2025
Acceptance Date
January 24, 2026
Published in Issue
Year 2026 Volume: 9 Number: 4