SONIC: Concurrent Oblivious RAM & Data Structures for Low-Latency and High-Throughput
Nihal Talur, Ioannis Demertzis
摘要
Relying solely on encryption for privacy-preserving computations is prone to leakage-abuse/access-pattern attacks. TEEs, while cost-effective, are also vulnerable to side-channel attacks. Oblivious primitives, such as oblivious memory (ORAM) and data structures (ODS) are effective building blocks to mitigate these risks by concealing memory access patterns and side-channel information. Applications range from private contact discovery (Signal) to anonymous key transparency, encrypted email search, encrypted/oblivious databases, anonymous communication (Sparta/SP'25), private federated learning, LLM privacy (Compass/OSDI'25), and broader confidential computing efforts. Tree-based ORAMs (EnigMap ( USENIX'23 ), GraphOS ( PVLDB'23 ), Oblix ( SP'18 )) offer low latency but limited parallelism, struggling to exceed 1K req/s throughput even for small datasets. Partition-based solutions like Snoopy ( SOSP'21 ) split data into multiple subORAMs, each parallel-scanning its shard via an oblivious hash table built from incoming requests, achieving high throughput by generously trading off latency—theoretically enabling linear scalability. In practice, Snoopy's performance hinges on how quickly each subORAM can complete its sequential scan before exceeding latency targets—constraining server utilization and throughput. While TB-scale datasets are theoretically feasible by adding servers, it requires 1000+ servers in practice. In this work , we reconcile the aforementioned fractured landscape between low-latency and high-throughput ORAM solutions. We introduce SONIC : the first ORAM for hardware enclaves that replaces PathORAM (used by EnigMap, GraphOS, and Oblix) with RingORAM. Our design is the first low-latency ORAM achieving minimum throughput of 150K req/s and up to 2M req/s (with one server), tackling core challenges of all tree-ORAM constructions (including RingORAM) such as overcoming the sequential eviction bottleneck, enabling efficient batch evictions, and providing lock-free access, reshuffle, and stash operations. SONIC achieves 28-197× higher ORAM access throughput than the open-source EnigMap implementation, and 158-1065× higher than GraphOS (for N=2 27 and block size 64 bytes). SONIC offers various methods to leverage ORAM concurrency for building oblivious data structures, such as OMAPs. Finally, SONIC can serve as a drop-in replacement for Snoopy's subORAM to provide more practical scalability— 1TB can now be handled with just 32 servers instead of thousands .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper41
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 被引用 649 次
- Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus InstabilityPhilip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li 等S&P 2020 · 被引用 607 次
- Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGXWenhao Wang, Guoxing Chen, Xiaorui Pan, Yinqian Zhang 等CCS 2017 · 被引用 403 次
相关 Paper
- Bulkor: Enabling Bulk Loading for Path ORAMXiang Li, Yunqian Luo, Mingyu GaoS&P 2024 · 被引用 8 次
- Treebeard: A Scalable and Fault Tolerant ORAM DatastoreAmin Setayesh, Cheran Mahalingam, Emily Chen, Sujaya MaiyyaUSENIX Security 2025
- QuORAM: A Quorum-Replicated Fault Tolerant ORAM DatastoreSujaya Maiyya, Seif Ibrahim, Caitlin Scarberry, Divyakant Agrawal 等USENIX Security 2022
- Onion Ring ORAM: Efficient Constant Bandwidth Oblivious RAM from (Leveled) TFHEHao Chen, Ilaria Chillotti, Ling RenCCS 2019 · 被引用 64 次
- ObliDB: Oblivious Query Processing for Secure DatabasesSaba Eskandarian, Matei ZahariaVLDB 2020 · 被引用 127 次
