A High-Throughput AES-GCM Implementation on GPUs for Secure, Policy-Based Access to Massive Astronomical Catalogs
arXiv:2602.23067 · doi:10.1016/j.ascom.2026.101153
Abstract
The era of large astronomical surveys generates massive image catalogs requiring efficient and secure access, particularly during pre-publication periods where data confidentiality and integrity are paramount. While Findable, Accessible, Interoperable, and Reusable (FAIR) principles guide the eventual public dissemination of data, traditional security methods for restricted phases often lack granularity or incur prohibitive performance penalties. To address this, we present a framework that integrates a flexible policy engine for fine-grained access control with a novel GPU-accelerated implementation of the AES-GCM authenticated encryption protocol. The novelty of this work lies in the adaptation and optimization of a parallel tree-reduction strategy to overcome the main performance bottleneck in authenticated encryption on GPUs: the inherently sequential Galois/Counter Mode (GCM) authentication hash (GHASH). We present both the algorithmic adaptation and its efficient execution on GPU architectures. Building on optimized GPU AES kernels from recent work in cryptographic acceleration, this work presents the first integration of these techniques into a high-throughput, FITS-aware encryption framework specifically designed for large-scale astronomical data, combining cryptographic authentication, dual-key access control, and direct compatibility with the standard astronomical Python ecosystem. Our implementation transforms the sequential GHASH computation into a highly parallelizable, logarithmic-time process, achieving authenticated encryption throughput suitable for petabyte-scale image analysis. Our solution provides a robust mechanism for data providers to enforce access policies, ensuring both confidentiality and integrity without hindering research workflows, thereby facilitating a secure and managed transition of data to public, FAIR archives.
Submitted to Astronomy and Computing. 18 pages, 5 figures
References in corpus (11)
- LSST: from Science Drivers to Reference Design and Anticipated Data Products
- The Zwicky Transient Facility: System Overview, Performance, and First Results
- BICEP2 I: Detection Of B-mode Polarization at Degree Angular Scales
- A Joint Analysis of BICEP2/Keck Array and Planck Data
- Representations of celestial coordinates in FITS
- Representations of world coordinates in FITS
- Discovery of a planetary-sized object in the scattered Kuiper belt
- ZTF Early Observations of Type Ia Supernovae I: Properties of the 2018 Sample
- Lossless Astronomical Image Compression and the Effects of Noise
- How Will Astronomy Archives Survive The Data Tsunami?
- Best Practices for Data Publication in the Astronomical Literature