Aria: Tolerating Skewed Workloads in Secure In-memory Key-value Stores
Fan Yang, Youmin Chen, Youyou Lu, Qing Wang, Jiwu Shu
Abstract
The recent advent of the hardware trusted execution environment (TEE), e.g., Intel SGX, enables encrypted and integrity-verified in-memory key-value (KV) stores. However, due to the architectural limitations of the hardware, it is nontrivial to build a secure in-memory KV store with SGX without compromising the performance. The reason comes from (i) the limited memory capacity the SGX TEE provides, and (ii) being unaware of the access patterns of skewed workloads, which are commonly seen in the real world.
In this paper, we present Aria, a secure in-memory KV store based on SGX. Our goal is to utilize the limited resource while still achieving high performance. Aria places KV pairs and index structures directly in the untrusted memory and introduces the security metadata in the TEE to conduct protection. The core component of Aria is Secure Cache, a software-based cache layer, which uses the limited memory resource to guarantee the confidentiality and integrity (including freshness) of Aria. Secure Cache keeps the frequently accessed security metadata in the TEE memory at fine-granularity and evicts rarely-used ones to the untrusted memory. With Secure Cache, we have the opportunities to explore strategies that are impossible in SGX implementation. By decoupling the security metadata management from the index structure, Aria supports various index schemes. We implement Aria with the indexes of both a hash table and a B-tree. Experiments show that Aria improves throughput by up to 104% compared to the state-of-the-art system.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 18ee73f9-c41f-4ad1-bab4-ede878bd2f8bCited by top-tier papers2
- Cosine: A Cloud-Cost Optimized Self-Designing Key-Value Storage EngineSubarna Chatterjee, Meena Jagadeesan, Wilson Qin, Stratos IdreosVLDB 2022 · 17 citations
- SACK: Shielding Dynamic Attribute-based Access Control in Persistent Key-Value StoresYanjing Ren, Jingwei Li, Patrick LeeVLDB 2026
Builds on7
- DRAMA: Exploiting DRAM Addressing for Cross-CPU AttacksPeter Pessl, Daniel Gruss, Clémentine Maurice, Michael Schwarz et al.USENIX Security 2016 · 500 citations
- EnclaveDB: A Secure Database Using SGXChristian Priebe, Kapil Vaswani, Manuel CostaS&P 2018 · 329 citations
- A large scale analysis of hundreds of in-memory cache clusters at TwitterJuncheng Yang, Yao Yue, K. V. RashmiOSDI 2020 · 245 citations
- The CacheLib Caching Engine: Design and Experiences at ScaleBenjamin Berg, Daniel S. Berger, Sara McAllister, Isaac Grosof et al.OSDI 2020 · 145 citations
- ObliDB: Oblivious Query Processing for Secure DatabasesSaba Eskandarian, Matei ZahariaVLDB 2020 · 127 citations
Related papers
- COIN Attacks: On Insecurity of Enclave Untrusted Interfaces in SGXMustakimur Rahman Khandaker, Yueqiang Cheng, Zhi Wang, Tao WeiASPLOS 2020 · 46 citations
- VeriDB: An SGX-based Verifiable DatabaseWenchao Zhou, Yifan Cai, Yanqing Peng, Sheng Wang et al.SIGMOD 2021 · 52 citations
- vSGX: Virtualizing SGX Enclaves on AMD SEVShixuan Zhao, Mengyuan Li, Yinqian Zhang, Zhiqiang LinS&P 2022 · 32 citations
- Elasticlave: An Efficient Memory Model for EnclavesJason Zhijingcheng Yu, Shweta Shinde, Trevor E. Carlson, Prateek SaxenaUSENIX Security 2022
- A Log-Structured Merge Tree-aware Message Authentication Scheme for Persistent Key-Value StoresIg-Jae Kim, J. Hyun Kim, Minu Chung, Hyungon Moon et al.FAST 2022 · 8 citations
