Avocado: A Secure In-Memory Distributed Storage System
Maurice Bailleu, Dimitra Giantsidi, Vasilis Gavrielatos, Do Le Quoc, Vijay Nagarajan, Pramod Bhatotia
Abstract
We introduce Avocado, a secure in-memory distributed storage system that provides strong security, fault-tolerance, consistency (linearizability) and performance for untrusted cloud environments. Avocado achieves these properties based on TEEs, which, however, are primarily designed for securing limited physical memory (enclave) within a single-node system. Avocado overcomes this limitation by extending the trust of a secure single-node enclave to the distributed environment over an untrusted network, while ensuring that replicas are kept consistent and fault-tolerant in a malicious environment.
To achieve these goals, we design and implement Avocado underpinning on the cross-layer contributions involving the network stack, the replication protocol, scalable trust establishment, and memory management. Avocado is practical: In comparison to BFT, Avocado provides confidentiality with fewer replicas and is significantly faster-4.5× to 65× for YCSB read and write heavy workloads, respectively.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7eeba6fd-19b6-4cf1-94ed-a0f1a4d5feb9Cited by top-tier papers16
- Confidential Consortium Framework: Secure Multiparty Applications with Confidentiality, Integrity, and High AvailabilityHeidi Howard, Fritz Alder, Edward Ashton, Amaury Chamayou et al.VLDB 2024 · 22 citations
- NARRATOR: Secure and Practical State Continuity for Trusted Execution in the CloudJianyu Niu, Wei Peng, Xiaokuan Zhang, Yinqian ZhangCCS 2022 · 21 citations
- uBFT: Microsecond-Scale BFT using Disaggregated MemoryMarcos K. Aguilera, Naama Ben-David, Rachid Guerraoui, Antoine Murat et al.ASPLOS 2023 · 20 citations
- ENGRAFT: Enclave-guarded Raft on Byzantine Faulty NodesWeili Wang, Sen Deng, Jianyu Niu, Michael K. Reiter et al.CCS 2022 · 19 citations
- FLARE: A Fast, Secure, and Memory-Efficient Distributed Analytics Framework (Flavor: Systems)Xiang Li, Fabing Li, Mingyu GaoVLDB 2023 · 14 citations
Builds on10
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic et al.EuroSys 2020 · 381 citations
Related papers
- Efficient Distributed Secure Memory with Migratable Merkle TreeErhu Feng, Dong Du, Yubin Xia, Haibo ChenHPCA 2023 · 14 citations
- RR: A Fault Model for Efficient TEE ReplicationBaltasar Dinis, Peter Druschel, Rodrigo RodriguesNDSS 2023
- Aria: Tolerating Skewed Workloads in Secure In-memory Key-value StoresFan Yang, Youmin Chen, Youyou Lu, Qing Wang et al.ICDE 2021 · 7 citations
- rkt-io: a direct I/O stack for shielded executionJörg Thalheim, Harshavardhan Unnibhavi, Christian Priebe, Pramod Bhatotia et al.EuroSys 2021 · 24 citations
- DISCO*: Distributed and SCalable Oblivious Joins and Oblivious PrimitivesApostolos Mavrogiannakis, Xian Wang, Ioannis Demertzis, Dimitrios Papadopoulos et al.SOSP 2026
