SACK: Shielding Dynamic Attribute-based Access Control in Persistent Key-Value Stores
Yanjing Ren, Jingwei Li, Patrick Lee
摘要
Enforcing fine-grained access control is critical for secure key-value (KV) stores in cloud environments, yet classical attribute-based encryption incurs significant overhead. We present SACK, a shielded framework leveraging Intel SGX to enable efficient, dynamic attribute-based access control (ABAC) for KV stores in untrusted cloud environments, while ensuring confidentiality, integrity, and freshness. SACK decouples access control and data management by performing ABAC with hardware-assisted shielded execution and leveraging KV separation for secure, efficient, and crash-consistent KV storage. We implement SACK as a middleware system that can run atop general KV stores. Experiments show that SACK achieves high-performance KV operations and lightweight renewal of access rights.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper12
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- EnclaveDB: A Secure Database Using SGXChristian Priebe, Kapil Vaswani, Manuel CostaS&P 2018 · 被引用 329 次
- ObliDB: Oblivious Query Processing for Secure DatabasesSaba Eskandarian, Matei ZahariaVLDB 2020 · 被引用 127 次
- SplinterDB: Closing the Bandwidth Gap for NVMe Key-Value StoresAlexander Conway, Abhishek Gupta, Vijay Chidambaram, Martin Farach-Colton 等USENIX ATC 2020 · 被引用 90 次
- OBFUSCURO: A Commodity Obfuscation Engine on Intel SGXAdil Ahmad, Byunggill Joe, Yuan Xiao, Yinqian Zhang 等NDSS 2019 · 被引用 83 次
相关 Paper
- Aria: Tolerating Skewed Workloads in Secure In-memory Key-value StoresFan Yang, Youmin Chen, Youyou Lu, Qing Wang 等ICDE 2021 · 被引用 7 次
- SGX-Shield: Enabling Address Space Layout Randomization for SGX ProgramsJaebaek Seo, Byoungyoung Lee, Seong-Min Kim, Ming-Wei Shih 等NDSS 2017 · 被引用 227 次
- ShieldReduce: Fine-Grained Shielded Data ReductionJingyuan Yang, Jun Wu, Ruilin Wu, Jingwei Li 等USENIX ATC 2025 · 被引用 3 次
- On the Practicality of Cryptographically Enforcing Dynamic Access Control Policies in the CloudWilliam C. Garrison III, Adam Shull, Steven A. Myers, Adam J. LeeS&P 2016 · 被引用 77 次
- SGXLock: Towards Efficiently Establishing Mutual Distrust Between Host Application and Enclave for SGXYuan Chen, Jiaqi Li, Guorui Xu, Yajin Zhou 等USENIX Security 2022
