MVP-ORAM: a Wait-free Concurrent ORAM for Confidential BFT Storage
Robin Vassantlal, Hasan Heydari, Bernardo Ferreira, Alysson Bessani
Abstract
It is well known that encryption alone is not enough to protect data privacy. Access patterns, revealed when operations are performed, can also be leveraged in inference attacks. Oblivious RAM (ORAM) hides access patterns by making client requests oblivious. However, existing protocols are still limited in supporting concurrent clients and Byzantine fault tolerance (BFT). We present MVP-ORAM, the first wait-free ORAM protocol that supports concurrent fail-prone clients. In contrast to previous works, MVP-ORAM avoids using trusted proxies, which necessitate additional security assumptions, and concurrency control mechanisms based on inter-client communication or distributed locks, which limit overall throughput and the capability to tolerate faulty clients. Instead, MVP-ORAM enables clients to perform concurrent requests and merge conflicting updates as they happen, satisfying wait-freedom, i.e., clients make progress independently of the performance or failures of other clients. Since wait and collision freedom are fundamentally contradictory goals that cannot be achieved simultaneously in an asynchronous concurrent ORAM service, we define a weaker notion of obliviousness that depends on the application workload and number of concurrent clients, and prove MVP-ORAM is secure in practical scenarios where clients perform skewed block accesses. By being wait-free, MVP-ORAM can be seamlessly integrated into existing confidential BFT data stores, creating the first BFT ORAM construction. We implement MVP-ORAM on top of a confidential BFT data store and show our prototype can process hundreds of 4KB accesses per second in modern clouds. This is the extended version of the paper published at the Proc. of the 33rd Network and Distributed System Security Symposium (NDSS 2026) [38].
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7b578402-a11f-4822-903d-205a7c8fc3b4Builds on23
- All Your Queries Are Belong to Us: The Power of File-Injection Attacks on Searchable EncryptionYupeng Zhang, Jonathan Katz, Charalampos PapamanthouUSENIX Security 2016 · 512 citations
- BEAT: Asynchronous BFT Made PracticalSisi Duan, Michael K. Reiter, Haibin ZhangCCS 2018 · 255 citations
- ZeroTrace : Oblivious Memory Primitives from Intel SGXSajin Sasy, Sergey Gorbunov, Christopher W. FletcherNDSS 2018 · 244 citations
- OBLIVIATE: A Data Oblivious Filesystem for Intel SGXAdil Ahmad, Kyungtae Kim, Muhammad Ihsanulhaq Sarfaraz, Byoungyoung LeeNDSS 2018 · 144 citations
- TaoStore: Overcoming Asynchronicity in Oblivious Data StorageCetin Sahin, Victor Zakhary, Amr El Abbadi, Huijia Lin et al.S&P 2016 · 98 citations
Related papers
- ConcurORAM: High-Throughput Stateless Parallel Multi-Client ORAMAnrin Chakraborti, Radu SionNDSS 2019 · 42 citations
- QuORAM: A Quorum-Replicated Fault Tolerant ORAM DatastoreSujaya Maiyya, Seif Ibrahim, Caitlin Scarberry, Divyakant Agrawal et al.USENIX Security 2022
- Towards Practical Oblivious JoinZhao Chang, Dong Xie, Sheng Wang, Feifei LiSIGMOD 2022 · 20 citations
- Multi-Range Supported Oblivious RAM for Efficient Block Data RetrievalYuezhi Che, Rujia WangHPCA 2020 · 16 citations
- rORAM: Efficient Range ORAM with O(log2 N) LocalityAnrin Chakraborti, Adam J. Aviv, Seung Geol Choi, Travis Mayberry et al.NDSS 2019 · 20 citations
