Published October 14, 2025 | Version v1
Conference paper Open

Understanding the Latency-Security Tradeoff: TEE-based Confidential Computing for Streaming Workloads

Description

Distributed streaming platforms such as Pravega, Kafka, and Pulsar are widely used for high-throughput, low latency data processing. As these platforms increasingly  handle sensitive data, ensuring data confidentiality and integrity becomes critical. Trusted Execution Environments (TEEs) offer secure computations that can be used on client-side processing, but their impact on performance must be carefully assessed. This study evaluates the write latency of Pravega clients running in TEEs compared to those in standard (non-secured) environments. We found that under typical workloads, TEE-based clients experience approximately 50% higher latency due to the overhead of secure executions. However, when data rates exceed 976 MB/s, the Pravega broker reaches its throughput limit, causing latency to spike for standard clients. In contrast, TEE-based clients exhibit more stable latency under these high-throughput conditions. These findings can be helpful for data architects, as systems highlight a trade-off: while latency may increase, the impact could be acceptable in certain scenarios given the enhanced security benefits.

Files

Dell_Scone_Kio_Paper.pdf

Files (1.1 MB)

Name Size Download all
md5:48e1dfa98a1a177b14e30b64f9ee2659
1.1 MB Preview Download

Additional details

Funding

European Commission
NEARDATA - Extreme Near-Data Processing Platform 101092644
European Commission
CloudSkin - Adaptive virtualization for AI-enabled Cloud-edge Continuum 101092646