TaoStore: Overcoming Asynchronicity in Oblivious Data Storage

TaoStore: Overcoming Asynchronicity in Oblivious Data Storage
复制标题

DOI:
10.1109/sp.2016.20
复制
发表时间:
2016-05
期刊:
2016 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Cetin Sahin;Victor Zakhary;A. E. Abbadi;Huijia Lin;Stefano Tessaro
Cetin Sahin;Victor Zakhary;A. E. Abbadi;Huijia Lin;Stefano Tessaro
中科院分区:
其他
文献类型:
--
作者:
Cetin Sahin;Victor Zakhary;A. E. Abbadi;Huijia Lin;Stefano Tessaro

文献摘要

被引文献

相似文献

我们认为不经意存储系统隐藏了数据的内容以及来自不可信云提供商的访问模式。我们的目标是这样一个场景,其中来自受信任组的多个用户(例如,公司雇员)通过协调客户端-云通信的可信代理异步访问和编辑潜在重叠的数据集。我们的论文的主要贡献是双重的。最重要的是,我们发起了第一个正式的研究不经意存储系统中的存储性。我们为客户端请求和网络通信都是异步的(事实上,甚至是对立的)场景提供了安全定义。虽然ObliviStore(Stefanov和Shi,S&P 2013)中的安全问题最近已经浮出水面,但我们的处理表明,这也是令人好奇的(Bindschaedler等人,CCS 2015),提出的确切目标是防止这些攻击,是不安全的异步调度下的网络通信。其次,我们开发和评估一个新的不经意存储系统,称为基于树的异步不经意存储,或简称TaoStore,我们证明了在异步环境中的安全。TaoStore构建在一个新的基于树的ORAM方案之上,该方案以非阻塞方式并发和异步地处理客户端请求。这导致在吞吐量,简单性和灵活性方面的大幅增益超过以前的系统。
We consider oblivious storage systems hiding both the contents of the data as well as access patterns from an untrusted cloud provider. We target a scenario where multiple users from a trusted group (e.g., corporate employees) asynchronously access and edit potentially overlapping data sets through a trusted proxy mediating client-cloud communication. The main contribution of our paper is twofold. Foremost, we initiate the first formal study of asynchronicity in oblivious storage systems. We provide security definitions for scenarios where both client requests and network communication are asynchronous (and in fact, even adversarially scheduled). While security issues in ObliviStore (Stefanov and Shi, S&P 2013) have recently been surfaced, our treatment shows that also CURIOUS (Bindschaedler at al., CCS 2015), proposed with the exact goal of preventing these attacks, is insecure under asynchronous scheduling of network communication. Second, we develop and evaluate a new oblivious storage system, called Tree-based Asynchronous Oblivious Store, or TaoStore for short, which we prove secure in asynchronous environments. TaoStore is built on top of a new tree-based ORAM scheme that processes client requests concurrently and asynchronously in a non-blocking fashion. This results in a substantial gain in throughput, simplicity, and flexibility over previous systems.