USENIX Security2026Top-tier venue
SONIC: Concurrent Oblivious RAM & Data Structures for Low-Latency and High-Throughput
Nihal Talur, Ioannis Demertzis
Abstract
Relying solely on encryption for privacy-preserving computations is prone to leakage-abuse/access-pattern attacks. TEEs, while cost-effective, are also vulnerable to side-channel attacks. Oblivious primitives, such as oblivious memory (ORAM) and data structures (ODS) are effective building blocks to mitigate these risks by concealing memory access patterns and side-channel information. Applications range from private contact discovery (Signal) to anonymous key transparency, encrypted email search, encrypted/oblivious databases, anonymous communication (Sparta/SP'25), private federated learning, LLM privacy (Compass/OSDI'25), and broader confidential computing efforts. Tree-based ORAMs (EnigMap ( USENIX'23 ), GraphOS ( PVLDB'23 ), Oblix ( SP'18 )) offer low latency but limited parallelism, struggling to exceed 1K req/s throughput even for small datasets. Partition-based solutions like Snoopy ( SOSP'21 ) split data into multiple subORAMs, each parallel-scanning its shard via an oblivious hash table built from incoming requests, achieving high throughput by generously trading off latency—theoretically enabling linear scalability. In practice, Snoopy's performance hinges on how quickly each subORAM can complete its sequential scan before exceeding latency targets—constraining server utilization and throughput. While TB-scale datasets are theoretically feasible by adding servers, it requires 1000+ servers in practice. In this work , we reconcile the aforementioned fractured landscape between low-latency and high-throughput ORAM solutions. We introduce SONIC : the first ORAM for hardware enclaves that replaces PathORAM (used by EnigMap, GraphOS, and Oblix) with RingORAM. Our design is the first low-latency ORAM achieving minimum throughput of 150K req/s and up to 2M req/s (with one server), tackling core challenges of all tree-ORAM constructions (including RingORAM) such as overcoming the sequential eviction bottleneck, enabling efficient batch evictions, and providing lock-free access, reshuffle, and stash operations. SONIC achieves 28-197× higher ORAM access throughput than the open-source EnigMap implementation, and 158-1065× higher than GraphOS (for N=2 27 and block size 64 bytes). SONIC offers various methods to leverage ORAM concurrency for building oblivious data structures, such as OMAPs. Finally, SONIC can serve as a drop-in replacement for Snoopy's subORAM to provide more practical scalability— 1TB can now be handled with just 32 servers instead of thousands .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 035560c2-779d-4f66-b852-9dd579e43871Builds on41
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus InstabilityPhilip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li et al.S&P 2020 · 607 citations
- Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGXWenhao Wang, Guoxing Chen, Xiaorui Pan, Yinqian Zhang et al.CCS 2017 · 403 citations
Related papers
- Bulkor: Enabling Bulk Loading for Path ORAMXiang Li, Yunqian Luo, Mingyu GaoS&P 2024 · 8 citations
- Treebeard: A Scalable and Fault Tolerant ORAM DatastoreAmin Setayesh, Cheran Mahalingam, Emily Chen, Sujaya MaiyyaUSENIX Security 2025
- QuORAM: A Quorum-Replicated Fault Tolerant ORAM DatastoreSujaya Maiyya, Seif Ibrahim, Caitlin Scarberry, Divyakant Agrawal et al.USENIX Security 2022
- Onion Ring ORAM: Efficient Constant Bandwidth Oblivious RAM from (Leveled) TFHEHao Chen, Ilaria Chillotti, Ling RenCCS 2019 · 64 citations
- ObliDB: Oblivious Query Processing for Secure DatabasesSaba Eskandarian, Matei ZahariaVLDB 2020 · 127 citations
