课题基金 / 基金详情

Scalable hardware-aided trusted data management

Scalable hardware-aided trusted data management
可扩展的硬件辅助可信数据管理
批准号:
361499254
负责人:
Professor Dr.-Ing. Rüdiger Kapitza
金额:
$0.0万
依托单位国家:
德国
项目类别:
Priority Programmes
财政年份:
2017
资助国家:
德国
项目状态:
已结题
起止时间:
2016-12-31 至 2021-12-31

项目摘要

项目成果

Professor Dr.-Ing. Rüdiger Kapitza的其他基金

相似基金

相关文献

中文摘要
翻译
将数据处理外包给外部数据中心(如云基础设施)已经变得无处不在,因为它对客户和提供商都有好处。但是,使用外部计算资源需要客户完全信任所提供的软件和硬件堆栈以及管理人员。当敏感数据应该被外部处理时,这形成了抑制剂,并且因此,已经提出了用于加密数据处理的初始解决方案。然而,他们都遭受个别的缺点,如有限的安全性,有限的表现力或性能penalments.Specifically基于软件的数据库管理系统(DBMS)的加密已被调查,然而,高性能的查询处理和安全的数据管理的背景下,新技术的可信执行打开了新的视角。因此,我们的项目旨在将可扩展数据管理与最新的硬件安全技术相结合,特别是英特尔Software Guard Extensions(SGX)。SGX增强了CPU的指令集,并允许创建所谓的“飞地”,这些飞地支持以本机性能在透明加密的主内存上进行计算。然而,现有的DBMS体系结构不知道这样的安全概念,并且它们的设计缺少在细粒度级别上引入可信计算所必需的灵活性。为了实现一个安全、灵活和可扩展的DBMS体系结构,我们推导了一个现代基于文档的DBMS体系结构模型,并将其划分为所需的可变空间w.r.t.用户定义的安全数据处理和DBMS加密的粒度,-用适合于硬件加密支持的功能来扩展该DBMS(例如,机密性和完整性保护)和安全意识,-通过识别和解决可信查询执行中的瓶颈(包括对存储器内缓冲策略的评估)来实现扩展,从而解决单个机器执行的空间限制,- 通过利用远程直接内存访问(RDMA),将我们的硬件辅助解决方案扩展到多台机器在这种情况下,我们有助于DFG优先级程序如下:首先,我们解决如何信任可以有效地添加到一个现代数据库系统。此外,我们增加了分布式计算能力,这个DBMS使用最近的硬件,没有得到最佳利用。这些步骤中的每一个都被集成到一个可扩展的体系结构模型中,该模型显式地表达了这些功能。其次,我们贡献的概念,降低可信计算的性能影响,使用分布式计算的RDMA。第三,我们打算扩展通用软件开发概念,以更好地解决可信计算问题。
英文摘要
Outsourcing data-processing to external data centres such as cloud infrastructures has become ubiquitous due to its benefits to both, customers and providers. However, using external compute resources requires customers to fully trust the provided software and hardware stack as well as the administrative staff. This forms an inhibitor when sensitive data should be externally processed, and as a consequence, initial solutions for encrypted data processing have been proposed. However, all of them suffer from individual shortcomings such as limited security, restricted expressiveness or performance penalties.Specifically software-based encryption in database management systems (DBMSs) has been investigated, however, high performance query processing and secure data management in the context of novel technologies for trusted execution opens new perspectives. Hence, our project targets the combination of scalable data management with recent hardware security technologies, in particular Intel Software Guard Extensions (SGX). SGX enhances the instruction set of the CPU and allows the creation of so called 'enclaves' that support computation on transparently encrypted main memory at native performance. However, existing DBMS architectures are unaware of such security concepts, and their designs miss the necessary flexibility to introduce trusted computing on a fine-grained level. Thus, we propose a tailorable architecture to address the contradicting demands of general-purpose high performance data management and secure data processing.In order to implement a secure, flexible and scalable DBMS architecture, we- derive an architecture model for modern document-based DBMSs, and partition it to span the required variability space w.r.t. the granularity of user-defined secure data processing and DBMS encryption,- extend this DBMS with functionality tailored to hardware encryption support (e.g., confidentiality and integrity protection) and security awareness,- enable scale-up by identifying and addressing bottlenecks in trusted query execution including evaluations of in-memory buffering strategies, thereby addressing space limitations for a single machine execution, and- enable scale-out of our hardware-aided solution to multiple machines by utilising remote direct memory access (RDMA) for distributed processing.In this context we contribute to the DFG priority program as follows: First, we address how trust can be efficiently added to a modern database system. In addition, we add distributed computing capabilities to this DBMS by using recent hardware that is not optimally utilised. Each of these steps are integrated into an extensible architecture model that explicitly expresses these features. Second, we contribute concepts for lowering the performance impact of trusted computing by using RDMA for distributed computing. Third, we intent to extend general purpose software development concepts to better address trusted computing.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
PRIMaTE: PRIvacy preserving Multi-compartment Trusted Execution
  • 批准号:
    391790956
  • 项目类别:
    Research Grants
  • 资助金额:
    $0.0万
  • 财政年份:
    2017
  • 负责人:
    Professor Dr.-Ing. Rüdiger Kapitza
  • 依托单位:
Resource efficient dynamic agreement and replication
Run-time environment for resource-scarce networked systems
Dependability Aspects in Configurable Embedded Operating Systems -- DanceOS
  • 批准号:
    182168484
  • 项目类别:
    Priority Programmes
  • 资助金额:
    $0.0万
  • 财政年份:
    2010
  • 负责人:
    Professor Dr.-Ing. Rüdiger Kapitza
  • 依托单位:
海外基金