A Multi-server ORAM Framework with Constant Client Bandwidth Blowup

A Multi-server ORAM Framework with Constant Client Bandwidth Blowup
复制标题

具有恒定客户端带宽爆炸的多服务器 ORAM 框架

DOI:
10.1145/3369108
复制
发表时间:
2020
影响因子:
2.3
通讯作者:
Guajardo, Jorge
Guajardo, Jorge
中科院分区:
计算机科学4区
文献类型:
--
作者:
Hoang, Thang;Yavuz, Attila A.;Guajardo, Jorge

文献摘要

参考文献

被引文献

相似文献

遗忘随机存取机(ORAM)允许客户端在访问远程服务器上的敏感数据时隐藏访问模式。众所周知,在任何被动ORAM结构上都存在对数通信下界,其中服务器仅充当存储服务。然而,对于某些应用程序来说,这种开销非常昂贵。为了克服这一限制,提出了几种带有服务器计算的主动ORAM方案。然而,它们主要依赖于昂贵的同态加密,其性能比被动ORAM更差。在本文中,我们提出了S3ORAM,这是一个新的多服务器ORAM框架,它具有so(1)客户端带宽膨胀和低客户端存储,而不依赖于昂贵的加密原语。我们的关键思想是在适用的二叉树- oram范式上利用Shamir秘密共享和多方乘法协议。该策略允许客户端指示服务器以低干预的方式代表他/她执行安全高效的计算,从而实现恒定的客户端带宽膨胀和低服务器计算开销。我们的框架也可以在一般树ORAM结构(k≥2)上工作。我们完全实现了我们的框架,并严格评估了其在商品云平台(Amazon EC2)上的性能。我们的综合实验证实了S3ORAM框架的效率,在中等网络带宽下,它比最有效的被动ORAM(即Path-ORAM)快大约10倍,同时比带宽放大0(1)的主动ORAM(即Onion-ORAM)快三个数量级。我们已经开源了我们的框架的实现,以供公众测试和调整。
Oblivious Random Access Machine (ORAM) allows a client to hide the access pattern when accessing sensitive data on a remote server. It is known that there exists a logarithmic communication lower bound on any passive ORAM construction, where the server only acts as the storage service. This overhead, however, was shown costly for some applications. Several active ORAM schemes with server computation have been proposed to overcome this limitation. However, they mostly rely on costly homomorphic encryptions, whose performance is worse than passive ORAM. In this article, we propose S3ORAM, a new multi-server ORAM framework, which featuresO(1) client bandwidth blowup and low client storage without relying on costly cryptographic primitives. Our key idea is to harness Shamir Secret Sharing and a multi-party multiplication protocol on applicable binary tree-ORAM paradigms. This strategy allows the client to instruct the server(s) to perform secure and efficient computation on his/her behalf with a low intervention thereby, achieving a constant client bandwidth blowup and low server computational overhead. Our framework can also work atop a generalk-ary tree ORAM structure (k≥ 2). We fully implemented our framework, and strictly evaluated its performance on a commodity cloud platform (Amazon EC2). Our comprehensive experiments confirmed the efficiency of S3ORAM framework, where it is approximately 10× faster than the most efficient passive ORAM (i.e., Path-ORAM) for a moderate network bandwidth while being three orders of magnitude faster than active ORAM withO(1) bandwidth blowup (i.e., Onion-ORAM). We have open-sourced the implementation of our framework for public testing and adaptation.
DOI: 10.1145/359168.359176
发表时间: 1979-01-01
影响因子: 22.7
作者:
SHAMIR, A
通讯作者: SHAMIR, A
可验证的不经意存储
DOI: --
发表时间: 2014
期刊: International Conference on Theory and Practice of Public Key Cryptography
影响因子: --
作者:
Daniel Apon;Jonathan Katz;E. Shi;Aishwarya Thiruvengadam
通讯作者: Aishwarya Thiruvengadam
用于安全计算的三方 ORAM
DOI: 10.1007/978-3-662-48797-6_16
发表时间: 2015
期刊: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Sky Faber;Stanislaw Jarecki;S. Kentros;Boyang Wei
通讯作者: Boyang Wei
多即是少:多服务器设置中完美安全的遗忘算法
DOI: --
发表时间: 2018
期刊: IACR Cryptology ePrint Archive
影响因子: --
作者:
T;Jonathan Katz;Kartik Nayak;Antigoni Polychroniadou;E. Shi
通讯作者: E. Shi
DOI: --
发表时间: 2017
期刊: International Conference on Theory and Practice of Public Key Cryptography
影响因子: --
作者:
Ittai Abraham;Christopher W. Fletcher;Kartik Nayak;Benny Pinkas;Ling Ren
通讯作者: Ling Ren