PrivateFS: a parallel oblivious file system

PrivateFS: a parallel oblivious file system
复制标题

DOI:
10.1145/2382196.2382299
复制
发表时间:
2012-10
期刊:
Proceedings of the 2012 ACM conference on Computer and communications security
影响因子:
--
通讯作者:
P. Williams;R. Sion;Alin Tomescu
P. Williams;R. Sion;Alin Tomescu
中科院分区:
其他
文献类型:
--
作者:
P. Williams;R. Sion;Alin Tomescu

文献摘要

被引文献

相似文献

PrivateFS是一个不经意的文件系统,它允许访问远程存储,同时保持文件内容和客户端访问模式的秘密。PrivateFS基于一种新的并行不经意RAM机制(PD-ORAM)--客户端线程现在可以并行地与服务器进行交互,而不会丢失隐私,而不是等待所有正在进行的客户端-服务器事务的完成。现有的不经意RAM(ORAM)中缺少这一关键部分,ORAM不能允许多个客户端线程同时操作,而不会显示查询内和查询间的相关性,从而导致隐私泄露。而且,由于ORAMs通常需要许多通信回合,这显著且不必要地限制了吞吐量。这里引入的机制消除了这个约束,允许总吞吐量仅受服务器带宽的约束,从而增加了一个数量级。此外,新的摊销技术使最坏情况下的查询成本与平均成本保持一致。这两个结果被证明是任何ORAM的基础。扩展提供对一个积极的恶意对手的分叉一致性。一个高性能,功能齐全的PD-ORAM实现的设计,建造和分析。它每秒在1 TB以上的数据库上跨50 ms延迟链路执行多个查询,具有未摊销的绑定查询延迟。PrivateFS基于PD-ORAM构建并部署在Linux上作为用户空间文件系统。
PrivateFS is an oblivious file system that enables access to remote storage, while keeping both the file contents and client access patterns secret. PrivateFS is based on a new parallel Oblivious RAM mechanism (PD-ORAM)---instead of waiting for the completion of all ongoing client-server transactions, client threads can now engage a server in parallel without loss of privacy. This critical piece is missing from existing Oblivious RAMs (ORAM), which can not allow multiple clients threads to operate simultaneously without revealing intra- and inter-query correlations and thus incurring privacy leaks. And since ORAMs often require many communication rounds, this significantly and unnecessarily constrains throughput. The mechanisms introduced here eliminate this constraint, allowing overall throughput to be bound by server bandwidth only, and thus to increase by an order of magnitude. Further, new de-amortization techniques bring the worst case query cost in line with the average cost. Both of these results are shown to be fundamental to any ORAM. Extensions providing fork consistency against an actively malicious adversary are then presented. A high performance, fully functional PD-ORAM implementation was designed, built and analyzed. It performs multiple queries per second on a 1TB+ database across 50ms latency links, with unamortized, bound query latencies. Based on PD-ORAM, PrivateFS was built and deployed on Linux as a userspace file system.