Waffle: An Online Oblivious Datastore for Protecting Data Access Patterns
Sujaya Maiyya, Sharath Chandra Vemula, Divyakant Agrawal, Amr El Abbadi, Florian Kerschbaum
Abstract
We present Waffle, a datastore that protects an application's data access patterns from a passive persistent adversary. Waffle achieves this without prior knowledge of the input data access distribution, making it the first of its kind to adaptively handle input sequences under a passive persistent adversary. Waffle maintains a constant bandwidth and client-side storage overhead, which can be adjusted to suit the application owner's preferences. This flexibility allows the owner to fine-tune system parameters and strike a balance between security and performance. Our evaluation, utilizing the Yahoo! Cloud Serving Benchmark (YCSB) benchmark and Redis as the backend storage, demonstrates promising results. The insecure baseline outperforms Waffle by a mere 5-6x, whereas Waffle outperforms Pancake-a state-of-the-art oblivious datastore under passive persistent adversaries-by 45-57%, and a concurrent ORAM system, TaoStore, by 102x.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2a4b92ad-a0e2-4019-ade3-9e05fd1edb57Cited by top-tier papers10
- SWAT: A System-Wide Approach to Tunable Leakage Mitigation in Encrypted Data StoresLeqian Zheng, Lei Xu, Cong Wang, Sheng Wang et al.VLDB 2024 · 8 citations
- OasisDB: An Oblivious and Scalable System for Relational DataHaseeb Ahmed, Nachiket Rao, Abdelkarim Kati, Florian Kerschbaum et al.VLDB 2025 · 2 citations
- Weave: Efficient and Expressive Oblivious Analytics at ScaleMahdi Soleimani, Grace Jia, Anurag KhandelwalOSDI 2025 · 1 citation
- Enabling Index-free Adjacency in Oblivious Graph Processing with Delayed DuplicationsWeiqi Feng, Xinle Cao, Adam O'Neill, Chuanhui YangVLDB 2026
- SONIC: Concurrent Oblivious RAM & Data Structures for Low-Latency and High-ThroughputNihal Talur, Ioannis DemertzisUSENIX Security 2026
Builds on14
- All Your Queries Are Belong to Us: The Power of File-Injection Attacks on Searchable EncryptionYupeng Zhang, Jonathan Katz, Charalampos PapamanthouUSENIX Security 2016 · 512 citations
- Generic Attacks on Secure Outsourced DatabasesGeorgios Kellaris, George Kollios, Kobbi Nissim, Adam O'NeillCCS 2016 · 327 citations
- Improved Reconstruction Attacks on Encrypted Data Using Range Query LeakageMarie-Sarah Lacharité, Brice Minaud, Kenneth G. PatersonS&P 2018 · 183 citations
- Pump up the Volume: Practical Database Reconstruction from Volume Leakage on Range QueriesPaul Grubbs, Marie-Sarah Lacharité, Brice Minaud, Kenneth G. PatersonCCS 2018 · 172 citations
- Hiding the Access Pattern is Not Enough: Exploiting Search Pattern Leakage in Searchable EncryptionSimon Oya, Florian KerschbaumUSENIX Security 2021 · 152 citations
Related papers
- Pancake: Frequency Smoothing for Encrypted Data StoresPaul Grubbs, Anurag Khandelwal, Marie-Sarah Lacharité, Lloyd Brown et al.USENIX Security 2020
- Treebeard: A Scalable and Fault Tolerant ORAM DatastoreAmin Setayesh, Cheran Mahalingam, Emily Chen, Sujaya MaiyyaUSENIX Security 2025
- QuORAM: A Quorum-Replicated Fault Tolerant ORAM DatastoreSujaya Maiyya, Seif Ibrahim, Caitlin Scarberry, Divyakant Agrawal et al.USENIX Security 2022
- Length Leakage in Oblivious Data Access MechanismsGrace Jia, Rachit Agarwal, Anurag KhandelwalUSENIX Security 2024 · 2 citations
- ObliviSync: Practical Oblivious File Backup and SynchronizationAdam J. Aviv, Seung Geol Choi, Travis Mayberry, Daniel S. RocheNDSS 2017 · 13 citations
