Implementing Zero-Trust Authentication and Authorization in Distributed Data Lake House Architectures

Authors

  • Surajit Paul

Keywords:

Access Control, Data Lake House, Fine-Grained Authorization, Identity Federation, Zero-Trust Architecture

Abstract

Distributed data lake house platforms connect business intelligence tools, distributed query engines, metadata catalogs, orchestration frameworks, and cloud object storage into a single analytical surface that spans hybrid and multi-cloud infrastructure. This disaggregation removes the network perimeter that earlier access control models assumed, and it leaves authentication and authorization scattered across components that each enforce a different native model: identity providers issue tokens, query engines apply engine-level roles, metadata catalogs hold table-level ownership, and storage systems apply bucket-level policies. No existing zero-trust reference model maps these control points onto a single, continuously verified architecture for a disaggregated lake house stack. This paper proposes a reference architecture that anchors fine-grained authorization at the metadata catalog, where the platform first has full semantic visibility into which tables, columns, and rows a request may reach, while identity federation and workload identity manage authentication upstream and downstream of that decision point. The architecture is evaluated against zero-trust tenets and compared with engine-native and storage-native enforcement alternatives on the basis of granularity, cross-engine consistency, and auditability. The paper also formalizes the latency cost of continuous verification and a composite behavioral risk score for detecting mid-query trust decay, and it closes with a discussion of the approach's limitations and the conditions under which catalog-anchored enforcement is the stronger design choice.

Downloads

Download data is not yet available.

References

Rose, Scott, Oliver Borchert, Stu Mitchell, and Sean Connelly. "Zero trust architecture." NIST special publication 800, no. 207 (2020): 1-52. https://doi.org/10.6028/NIST.SP.800-207

Kindervag, John, S. Balaouras, K. Mak, and J. Blackborow. "No more chewy centers: The zero trust model of information security." Forrester Research 23 (2016). https://crystaltechnologies.com/wp-content/uploads/2017/12/forrester-zero-trust-model-information-security.pdf

Ward, R. and Beyer, B., 2014. Beyondcorp: A new approach to enterprise security. USENIX ;login:, 39(6), pp.6-11. https://www.usenix.org/system/files/login/articles/login_dec14_02_ward.pdf

Lampson, Butler, Martin Abadi, Michael Burrows, and Edward Wobber. "Authentication in distributed systems: Theory and practice." ACM Transactions on Computer Systems (TOCS) 10, no. 4 (1992): 265-310. https://dl.acm.org/doi/abs/10.1145/138873.138874

Chandramouli, Ramaswamy, and Zack Butcher. A zero trust architecture model for access control in cloud-native applications in multi-cloud environments. No. NIST Special Publication (SP) 800-207A. National Institute of Standards and Technology, 2023. https://csrc.nist.gov/pubs/sp/800/207/a/final

Hu, Vincent C., David Ferraiolo, Rick Kuhn, Arthur R. Friedman, Alan J. Lang, Margaret M. Cogdell, Adam Schnitzer, Kenneth Sandlin, Robert Miller, and Karen Scarfone. "Guide to attribute based access control (abac) definition and considerations (draft)." NIST special publication 800, no. 162 (2013): 1-54. https://book.ole12138.cn/Book/Guide%20to%20attribute%20based%20access%20control%20%28abac%29%20definition%20and%20considerations.pdf

Hardt, Dick. The OAuth 2.0 authorization framework. No. rfc6749. 2012. Available: https://www.rfc-editor.org/info/rfc6749/

Sakimura, Nat, John Bradley, Mike Jones, Breno De Medeiros, and Chuck Mortimore. "OpenID Connect Core 1.0 incorporating errata set 1." The OpenID Foundation, specification 335 (2014). https://openid.net/specs/openid-connect-core-1_0.html

Rescorla, Eric. The transport layer security (TLS) protocol version 1.3. No. rfc8446. 2018. https://www.rfc-editor.org/info/rfc8446/

Pang, Ruoming, Ramon Caceres, Mike Burrows, Zhifeng Chen, Pratik Dave, Nathan Germer, Alexander Golynski et al. "Zanzibar: Google's Consistent, Global Authorization System." In 2019 USENIX Annual Technical Conference (USENIX ATC 19), pp. 33-46. 2019. https://www.usenix.org/conference/atc19/presentation/pang

Sethi, Raghav, Martin Traverso, Dain Sundstrom, David Phillips, Wenlei Xie, Yutian James Sun, Nezih Yigitbasi, Haozhun Jin, Eric Hwang, Nileema Shingte, and Christopher Berner. "Presto: SQL on Everything." In Proc. IEEE 35th International Conference on Data Engineering (ICDE), Macao, China, 2019, pp. 1802-1813. https://ieeexplore.ieee.org/abstract/document/8731547

Cloud Native Computing Foundation, "Cloud Native Security Whitepaper," Version 2, CNCF, San Francisco, CA, USA, 2022. https://www.cncf.io/wp-content/uploads/2022/06/CNCF_cloud-native-security-whitepaper-May2022-v2.pdf

Armbrust, Michael, Ali Ghodsi, Reynold Xin, and Matei Zaharia. "Lakehouse: a new generation of open platforms that unify data warehousing and advanced analytics." In Proceedings of CIDR, vol. 8, no. 1, p. 28. 2021. https://15721.courses.cs.cmu.edu/spring2023/papers/02-modern/armbrust-cidr21.pdf

Syed, Naeem Firdous, Syed W. Shah, Arash Shaghaghi, Adnan Anwar, Zubair Baig, and Robin Doss. "Zero trust architecture (zta): A comprehensive survey." IEEE access 10 (2022): 57143-57179. https://ieeexplore.ieee.org/abstract/document/9773102

Deochake, Saurabh, and Vrushali Channapattan. "Identity and access management framework for multi-tenant resources in hybrid cloud computing." In Proceedings of the 17th International Conference on Availability, Reliability and Security, pp. 1-8. 2022. https://dl.acm.org/doi/abs/10.1145/3538969.3544896

Cybersecurity and Infrastructure Security Agency, "Zero Trust Maturity Model," Version 2.0, CISA, Washington, DC, USA, 2023. https://www.cisa.gov/sites/default/files/2023-04/CISA_Zero_Trust_Maturity_Model_Version_2_508c.pdf

IBM. Cost of a Data Breach Report 2025. 2025. https://www.ibm.com/reports/data-breach

Luxner, Tanner. "Cloud computing trends: Flexera 2024 State of the Cloud Report," Flexera, 2024. https://www.flexera.com/blog/finops/cloud-computing-trends-flexera-2024-state-of-the-cloud-report/

Singh, Shubham, Cristina Hava Muntean, and Shaguna Gupta. "Resilient microservices: an investigation into Istio effectiveness in Kubernetes." Cluster Computing 29, no. 1 (2026): 27. https://link.springer.com/article/10.1007/s10586-025-05750-x

Weinberg, Abraham Itzhak, and Kelly Cohen. "Zero Trust Implementation in the Emerging Technologies Era: Survey." arXiv e-prints (2024): arXiv-2401. https://ui.adsabs.harvard.edu/abs/2024arXiv240109575I/abstract

Downloads

Published

15.07.2026

How to Cite

Surajit Paul. (2026). Implementing Zero-Trust Authentication and Authorization in Distributed Data Lake House Architectures. International Journal of Intelligent Systems and Applications in Engineering, 14(1s), 2082 –. Retrieved from https://www.ijisae.org/index.php/IJISAE/article/view/8470

Issue

Section

Research Article