Implementing Zero-Trust Authentication and Authorization in Distributed Data Lake House Architectures
Keywords:
Access Control, Data Lake House, Fine-Grained Authorization, Identity Federation, Zero-Trust ArchitectureAbstract
Distributed data lake house platforms connect business intelligence tools, distributed query engines, metadata catalogs, orchestration frameworks, and cloud object storage into a single analytical surface that spans hybrid and multi-cloud infrastructure. This disaggregation removes the network perimeter that earlier access control models assumed, and it leaves authentication and authorization scattered across components that each enforce a different native model: identity providers issue tokens, query engines apply engine-level roles, metadata catalogs hold table-level ownership, and storage systems apply bucket-level policies. No existing zero-trust reference model maps these control points onto a single, continuously verified architecture for a disaggregated lake house stack. This paper proposes a reference architecture that anchors fine-grained authorization at the metadata catalog, where the platform first has full semantic visibility into which tables, columns, and rows a request may reach, while identity federation and workload identity manage authentication upstream and downstream of that decision point. The architecture is evaluated against zero-trust tenets and compared with engine-native and storage-native enforcement alternatives on the basis of granularity, cross-engine consistency, and auditability. The paper also formalizes the latency cost of continuous verification and a composite behavioral risk score for detecting mid-query trust decay, and it closes with a discussion of the approach's limitations and the conditions under which catalog-anchored enforcement is the stronger design choice.
Downloads
References
Rose, Scott, Oliver Borchert, Stu Mitchell, and Sean Connelly. "Zero trust architecture." NIST special publication 800, no. 207 (2020): 1-52. https://doi.org/10.6028/NIST.SP.800-207
Kindervag, John, S. Balaouras, K. Mak, and J. Blackborow. "No more chewy centers: The zero trust model of information security." Forrester Research 23 (2016). https://crystaltechnologies.com/wp-content/uploads/2017/12/forrester-zero-trust-model-information-security.pdf
Ward, R. and Beyer, B., 2014. Beyondcorp: A new approach to enterprise security. USENIX ;login:, 39(6), pp.6-11. https://www.usenix.org/system/files/login/articles/login_dec14_02_ward.pdf
Lampson, Butler, Martin Abadi, Michael Burrows, and Edward Wobber. "Authentication in distributed systems: Theory and practice." ACM Transactions on Computer Systems (TOCS) 10, no. 4 (1992): 265-310. https://dl.acm.org/doi/abs/10.1145/138873.138874
Chandramouli, Ramaswamy, and Zack Butcher. A zero trust architecture model for access control in cloud-native applications in multi-cloud environments. No. NIST Special Publication (SP) 800-207A. National Institute of Standards and Technology, 2023. https://csrc.nist.gov/pubs/sp/800/207/a/final
Hu, Vincent C., David Ferraiolo, Rick Kuhn, Arthur R. Friedman, Alan J. Lang, Margaret M. Cogdell, Adam Schnitzer, Kenneth Sandlin, Robert Miller, and Karen Scarfone. "Guide to attribute based access control (abac) definition and considerations (draft)." NIST special publication 800, no. 162 (2013): 1-54. https://book.ole12138.cn/Book/Guide%20to%20attribute%20based%20access%20control%20%28abac%29%20definition%20and%20considerations.pdf
Hardt, Dick. The OAuth 2.0 authorization framework. No. rfc6749. 2012. Available: https://www.rfc-editor.org/info/rfc6749/
Sakimura, Nat, John Bradley, Mike Jones, Breno De Medeiros, and Chuck Mortimore. "OpenID Connect Core 1.0 incorporating errata set 1." The OpenID Foundation, specification 335 (2014). https://openid.net/specs/openid-connect-core-1_0.html
Rescorla, Eric. The transport layer security (TLS) protocol version 1.3. No. rfc8446. 2018. https://www.rfc-editor.org/info/rfc8446/
Pang, Ruoming, Ramon Caceres, Mike Burrows, Zhifeng Chen, Pratik Dave, Nathan Germer, Alexander Golynski et al. "Zanzibar: Google's Consistent, Global Authorization System." In 2019 USENIX Annual Technical Conference (USENIX ATC 19), pp. 33-46. 2019. https://www.usenix.org/conference/atc19/presentation/pang
Sethi, Raghav, Martin Traverso, Dain Sundstrom, David Phillips, Wenlei Xie, Yutian James Sun, Nezih Yigitbasi, Haozhun Jin, Eric Hwang, Nileema Shingte, and Christopher Berner. "Presto: SQL on Everything." In Proc. IEEE 35th International Conference on Data Engineering (ICDE), Macao, China, 2019, pp. 1802-1813. https://ieeexplore.ieee.org/abstract/document/8731547
Cloud Native Computing Foundation, "Cloud Native Security Whitepaper," Version 2, CNCF, San Francisco, CA, USA, 2022. https://www.cncf.io/wp-content/uploads/2022/06/CNCF_cloud-native-security-whitepaper-May2022-v2.pdf
Armbrust, Michael, Ali Ghodsi, Reynold Xin, and Matei Zaharia. "Lakehouse: a new generation of open platforms that unify data warehousing and advanced analytics." In Proceedings of CIDR, vol. 8, no. 1, p. 28. 2021. https://15721.courses.cs.cmu.edu/spring2023/papers/02-modern/armbrust-cidr21.pdf
Syed, Naeem Firdous, Syed W. Shah, Arash Shaghaghi, Adnan Anwar, Zubair Baig, and Robin Doss. "Zero trust architecture (zta): A comprehensive survey." IEEE access 10 (2022): 57143-57179. https://ieeexplore.ieee.org/abstract/document/9773102
Deochake, Saurabh, and Vrushali Channapattan. "Identity and access management framework for multi-tenant resources in hybrid cloud computing." In Proceedings of the 17th International Conference on Availability, Reliability and Security, pp. 1-8. 2022. https://dl.acm.org/doi/abs/10.1145/3538969.3544896
Cybersecurity and Infrastructure Security Agency, "Zero Trust Maturity Model," Version 2.0, CISA, Washington, DC, USA, 2023. https://www.cisa.gov/sites/default/files/2023-04/CISA_Zero_Trust_Maturity_Model_Version_2_508c.pdf
IBM. Cost of a Data Breach Report 2025. 2025. https://www.ibm.com/reports/data-breach
Luxner, Tanner. "Cloud computing trends: Flexera 2024 State of the Cloud Report," Flexera, 2024. https://www.flexera.com/blog/finops/cloud-computing-trends-flexera-2024-state-of-the-cloud-report/
Singh, Shubham, Cristina Hava Muntean, and Shaguna Gupta. "Resilient microservices: an investigation into Istio effectiveness in Kubernetes." Cluster Computing 29, no. 1 (2026): 27. https://link.springer.com/article/10.1007/s10586-025-05750-x
Weinberg, Abraham Itzhak, and Kelly Cohen. "Zero Trust Implementation in the Emerging Technologies Era: Survey." arXiv e-prints (2024): arXiv-2401. https://ui.adsabs.harvard.edu/abs/2024arXiv240109575I/abstract
Downloads
Published
How to Cite
Issue
Section
License

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
All papers should be submitted electronically. All submitted manuscripts must be original work that is not under submission at another journal or under consideration for publication in another form, such as a monograph or chapter of a book. Authors of submitted papers are obligated not to submit their paper for publication elsewhere until an editorial decision is rendered on their submission. Further, authors of accepted papers are prohibited from publishing the results in other publications that appear before the paper is published in the Journal unless they receive approval for doing so from the Editor-In-Chief.
IJISAE open access articles are licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. This license lets the audience to give appropriate credit, provide a link to the license, and indicate if changes were made and if they remix, transform, or build upon the material, they must distribute contributions under the same license as the original.


