Lune

NDSS2018顶会

ZeroTrace : Oblivious Memory Primitives from Intel SGX

Sajin Sasy, Sergey Gorbunov, Christopher W. Fletcher

2018年份
244被引次数
63顶会引用

摘要

We are witnessing a confluence between applied cryptography and secure hardware systems in enabling secure cloud computing.On one hand, work in applied cryptography has enabled efficient, oblivious data-structures and memory primitives.On the other, secure hardware and the emergence of Intel SGX has enabled a low-overhead and mass market mechanism for isolated execution.By themselves these technologies have their disadvantages.Oblivious memory primitives carry high performance overheads, especially when run non-interactively.Intel SGX, while more efficient, suffers from numerous softwarebased side-channel attacks, high context switching costs, and bounded memory size.In this work we build a new library of oblivious memory primitives, which we call ZeroTrace.ZeroTrace is designed to carefully combine state-of-the-art oblivious RAM techniques and SGX, while mitigating individual disadvantages of these technologies.To the best of our knowledge, ZeroTrace represents the first oblivious memory primitives running on a real secure hardware platform.ZeroTrace simultaneously enables a dramatic speed-up over pure cryptography and protection from softwarebased side-channel attacks.The core of our design is an efficient and flexible block-level memory controller that provides oblivious execution against any active software adversary, and across asynchronous SGX enclave terminations.Performance-wise, the memory controller can service requests for 4 B blocks in 1.2 ms and 1 KB blocks in 3.4 ms (given a 10 GB dataset).On top of our memory controller, we evaluate Set/Dictionary/List interfaces which can all perform basic operations (e.g., get/put/insert). A. This WorkWe address this challenge by designing and implementing ZeroTrace -an oblivious library enabling applications to be built out of fine-grained building-blocks at the application's data-structure interface boundary.Any operation on the data stored by the library is protected using SGX enclaves and remains secure against all software attacks, including all known side-channels.Partitioning applications at the oblivious data-structure boundary hits a sweet spot for several reasons.First, the data-structure interface is narrow, which makes it easier to sanitize application to data-structure requests-improving intra-Network and

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper63

问问它们各自怎么用它

它引用的顶会 Paper9

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖