SACK: Shielding Dynamic Attribute-based Access Control in Persistent Key-Value Stores
Yanjing Ren, Jingwei Li, Patrick Lee
Abstract
Enforcing fine-grained access control is critical for secure key-value (KV) stores in cloud environments, yet classical attribute-based encryption incurs significant overhead. We present SACK, a shielded framework leveraging Intel SGX to enable efficient, dynamic attribute-based access control (ABAC) for KV stores in untrusted cloud environments, while ensuring confidentiality, integrity, and freshness. SACK decouples access control and data management by performing ABAC with hardware-assisted shielded execution and leveraging KV separation for secure, efficient, and crash-consistent KV storage. We implement SACK as a middleware system that can run atop general KV stores. Experiments show that SACK achieves high-performance KV operations and lightweight renewal of access rights.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ab7a76cd-baa3-4841-9047-ef3a0cdbd779Builds on12
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- EnclaveDB: A Secure Database Using SGXChristian Priebe, Kapil Vaswani, Manuel CostaS&P 2018 · 329 citations
- ObliDB: Oblivious Query Processing for Secure DatabasesSaba Eskandarian, Matei ZahariaVLDB 2020 · 127 citations
- SplinterDB: Closing the Bandwidth Gap for NVMe Key-Value StoresAlexander Conway, Abhishek Gupta, Vijay Chidambaram, Martin Farach-Colton et al.USENIX ATC 2020 · 90 citations
- OBFUSCURO: A Commodity Obfuscation Engine on Intel SGXAdil Ahmad, Byunggill Joe, Yuan Xiao, Yinqian Zhang et al.NDSS 2019 · 83 citations
Related papers
- Aria: Tolerating Skewed Workloads in Secure In-memory Key-value StoresFan Yang, Youmin Chen, Youyou Lu, Qing Wang et al.ICDE 2021 · 7 citations
- SGX-Shield: Enabling Address Space Layout Randomization for SGX ProgramsJaebaek Seo, Byoungyoung Lee, Seong-Min Kim, Ming-Wei Shih et al.NDSS 2017 · 227 citations
- ShieldReduce: Fine-Grained Shielded Data ReductionJingyuan Yang, Jun Wu, Ruilin Wu, Jingwei Li et al.USENIX ATC 2025 · 3 citations
- On the Practicality of Cryptographically Enforcing Dynamic Access Control Policies in the CloudWilliam C. Garrison III, Adam Shull, Steven A. Myers, Adam J. LeeS&P 2016 · 77 citations
- SGXLock: Towards Efficiently Establishing Mutual Distrust Between Host Application and Enclave for SGXYuan Chen, Jiaqi Li, Guorui Xu, Yajin Zhou et al.USENIX Security 2022
