MOSE: Practical Multi-User Oblivious Storage via Secure Enclaves

MOSE: Practical Multi-User Oblivious Storage via Secure Enclaves
复制标题

DOI:
10.1145/3374664.3375749
复制
发表时间:
2020-03
期刊:
Proceedings of the Tenth ACM Conference on Data and Application Security and Privacy
影响因子:
--
通讯作者:
Thang Hoang;R. Behnia;Yeongjin Jang;A. Yavuz
Thang Hoang;R. Behnia;Yeongjin Jang;A. Yavuz
中科院分区:
其他
文献类型:
--
作者:
Thang Hoang;R. Behnia;Yeongjin Jang;A. Yavuz

文献摘要

被引文献

相似文献

多用户不经意存储允许用户访问云上的共享数据,同时保留访问模式不经意性和数据机密性。大多数安全且高效的不经意存储系统都注重利用最大网络带宽来通过可信代理提供并发访问服务。然而,由于代理通过网络执行标准 ORAM 协议,因此性能受到网络带宽和延迟的限制。此外,在此类代理设置中,一些重要功能(例如访问控制和针对主动对手的安全性)尚未得到彻底探索。在本文中,我们提出了 MOSE,一种多用户不经意存储系统,该系统高效且具有一些理想的安全特性。我们的主要想法是利用驻留在不受信任的存储服务器上的安全飞地(即英特尔SGX)来执行代理逻辑,从而最大限度地减少基于代理的设计的网络瓶颈。在这方面,我们解决了在安全飞地中启用代理逻辑时的各种技术设计挑战,例如内存限制、旁道攻击和可扩展性问题。我们提出了具有访问控制的安全飞地多用户 ORAM 的正式安全模型和分析。我们优化 MOSE 以提高其处理并发请求的吞吐量。我们实施了 MOSE 并评估了其在商用硬件上的性能。我们的评估证实了 MOSE 的效率,它的吞吐量比最先进的基于代理的设计高出大约两个数量级,而且其性能可与可用系统资源成比例地扩展。
Multi-user oblivious storage allows users to access their shared data on the cloud while retaining access pattern obliviousness and data confidentiality simultaneously. Most secure and efficient oblivious storage systems focus on the utilization of the maximum network bandwidth in serving concurrent accesses via a trusted proxy. How- ever, since the proxy executes a standard ORAM protocol over the network, the performance is capped by the network bandwidth and latency. Moreover, some important features such as access control and security against active adversaries have not been thoroughly explored in such proxy settings. In this paper, we propose MOSE, a multi-user oblivious storage system that is efficient and enjoys from some desirable security properties. Our main idea is to harness a secure enclave, namely Intel SGX, residing on the untrusted storage server to execute proxy logic, thereby, minimizing the network bottleneck of proxy-based designs. In this regard, we address various technical design chal- lenges such as memory constraints, side-channel attacks and scala- bility issues when enabling proxy logic in the secure enclave. We present a formal security model and analysis for secure enclave multi-user ORAM with access control. We optimize MOSE to boost its throughput in serving concurrent requests. We implemented MOSE and evaluated its performance on commodity hardware. Our evaluation confirmed the efficiency of MOSE, where it achieves approximately two orders of magnitudes higher throughput than the state-of-the-art proxy-based design, and also, its performance is scalable proportional to the available system resources.