SGX-BigMatrix: A Practical Encrypted Data Analytic Framework With Trusted Processors
Fahad Shaon, Murat Kantarcioglu, Zhiqiang Lin, Latifur Khan
Abstract
Recently, using secure processors for trusted computing in cloud has attracted a lot of attention. Over the past few years, efficient and secure data analytic tools (e.g., map-reduce framework, machine learning models, and SQL querying) that can be executed over encrypted data using the trusted hardware have been developed. However, these prior efforts do not provide a simple, secure and high level language based framework that is suitable for enabling generic data analytics for non-security experts who do not have concepts such as "oblivious execution". In this paper, we thus provide such a framework that allows data scientists to perform the data analytic tasks with secure processors using a Python/Matlablike high level language. Our framework automatically compiles programs written in our language to optimal execution code by managing issues such as optimal data block sizes for I/O, vectorized computations to simplify much of the data processing, and optimal ordering of operations for certain tasks. Furthermore, many language constructs such as if-statements are removed so that a non-expert user is less likely to create a piece of code that may reveal sensitive information while allowing oblivious data processing (i.e., hiding access patterns). Using these design choices, we provide guarantees for efficient and secure data analytics. We show that our framework can be used to run the existing big data benchmark queries over encrypted data using the Intel SGX efficiently. Our empirical results indicate that our proposed framework is orders of magnitude faster than the general oblivious execution alternatives. CCS CONCEPTS • Security and privacy → Management and querying of encrypted data;
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a597edf4-deef-4692-8fa3-47540cd4b644Cited by top-tier papers15
- Data Oblivious ISA Extensions for Side Channel-Resistant and High Performance ComputingJiyong Yu, Lucas Hsiung, Mohamad El Hajj, Christopher W. FletcherNDSS 2019 · 106 citations
- LightBox: Full-stack Protected Stateful Middlebox at Lightning SpeedHuayi Duan, Cong Wang, Xingliang Yuan, Yajin Zhou et al.CCS 2019 · 88 citations
- Speculative Data-Oblivious Execution: Mobilizing Safe Prediction For Safe and Efficient Speculative ExecutionJiyong Yu, Namrata Mantri, Josep Torrellas, Adam Morrison et al.ISCA 2020 · 50 citations
- Virtual Secure Platform: A Five-Stage Pipeline Processor over TFHEKotaro Matsuoka, Ryotaro Banno, Naoki Matsumoto, Takashi Sato et al.USENIX Security 2021 · 38 citations
- Speculative Privacy Tracking (SPT): Leaking Information From Speculative Execution Without Compromising PrivacyRutvik Choudhary, Jiyong Yu, Christopher W. Fletcher, Adam MorrisonMICRO 2021 · 33 citations
Builds on2
- Oblivious Multi-Party Machine Learning on Trusted ProcessorsOlga Ohrimenko, Felix Schuster, Cédric Fournet, Aastha Mehta et al.USENIX Security 2016 · 594 citations
- T-SGX: Eradicating Controlled-Channel Attacks Against Enclave ProgramsMing-Wei Shih, Sangho Lee, Taesoo Kim, Marcus PeinadoNDSS 2017 · 431 citations
Related papers
- FLARE: A Fast, Secure, and Memory-Efficient Distributed Analytics Framework (Flavor: Systems)Xiang Li, Fabing Li, Mingyu GaoVLDB 2023 · 14 citations
- Generalized Policy-Based Noninterference for Efficient Confidentiality-PreservationShamiek Mangipudi, Pavel Chuprikov, Patrick Eugster, Malte Viering et al.PLDI 2023 · 3 citations
- Weave: Efficient and Expressive Oblivious Analytics at ScaleMahdi Soleimani, Grace Jia, Anurag KhandelwalOSDI 2025 · 1 citation
- Shechi: A Secure Distributed Computation Compiler Based on Multiparty Homomorphic EncryptionHaris Smajlovic, David Froelicher, Ariya Shajii, Bonnie Berger et al.USENIX Security 2025
- Silph: A Framework for Scalable and Accurate Generation of Hybrid MPC ProtocolsEdward Chen, Jinhao Zhu, Alex Ozdemir, Riad S. Wahby et al.S&P 2023
