Building Enclave-Native Storage Engines for Practical Encrypted Databases
Yuanyuan Sun, Sheng Wang, Huorong Li, Feifei Li
摘要
Data confidentiality is one of the biggest concerns that hinders enterprise customers from moving their workloads to the cloud. Thanks to the trusted execution environment (TEE), it is now feasible to build encrypted databases in the enclave that can process customers' data while keeping it confidential to the cloud. Though some enclave-based encrypted databases emerge recently, there remains a large unexplored area in between about how confidentiality can be achieved in different ways and what influences are implied by them. In this paper, we first provide a broad exploration of possible design choices in building encrypted database storage engines, rendering trade-offs in security, performance and functionality. We observe that choices on different dimensions can be independent and their combination determines the overall trade-off of the entire storage. We then propose Enclage , an encrypted storage engine that makes practical trade-offs. It adopts many enclave-native designs, such as page-level encryption, reduced enclave interaction, and hierarchical memory buffer, which offer high-level security guarantee and high performance at the same time. To make better use of the limited enclave memory, we derive the optimal page size in enclave and adopt delta decryption to access large data pages with low cost. Our experiments show that Enclage outperforms the baseline, a common storage design in many encrypted databases, by over 13x in throughput and about 5x in storage savings.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper17
- Pantheon: Private Retrieval from Public Key-Value StoreIshtiyaque Ahmad, Divyakant Agrawal, Amr El Abbadi, Trinabh GuptaVLDB 2023 · 被引用 23 次
- Confidential Consortium Framework: Secure Multiparty Applications with Confidentiality, Integrity, and High AvailabilityHeidi Howard, Fritz Alder, Edward Ashton, Amaury Chamayou 等VLDB 2024 · 被引用 22 次
- Data Station: Delegated, Trustworthy, and Auditable Computation to Enable Data-Sharing Consortia with a Data EscrowSiyuan Xia, Zhiru Zhu, Chris Zhu, Jinjin Zhao 等VLDB 2022 · 被引用 17 次
- Compass: Encrypted Semantic Search with High AccuracyJinhao Zhu, Liana Patel, Matei Zaharia, Raluca Ada PopaOSDI 2025 · 被引用 14 次
- What Is the Price for Joining Securely? Benchmarking Equi-Joins in Trusted Execution EnvironmentsKajetan Jeremi Maliszewski, Jorge-Arnulfo Quiané-Ruiz, Jonas Traub, Volker MarklVLDB 2022 · 被引用 13 次
它引用的顶会 Paper6
- EnclaveDB: A Secure Database Using SGXChristian Priebe, Kapil Vaswani, Manuel CostaS&P 2018 · 被引用 329 次
- Oblix: An Efficient Oblivious Search IndexPratyush Mishra, Rishabh Poddar, Jerry Chen, Alessandro Chiesa 等S&P 2018 · 被引用 200 次
- CacheOut: Leaking Data on Intel CPUs via Cache EvictionsStephan van Schaik, Marina Minkin, Andrew Kwong, Daniel Genkin 等S&P 2021 · 被引用 158 次
- ObliDB: Oblivious Query Processing for Secure DatabasesSaba Eskandarian, Matei ZahariaVLDB 2020 · 被引用 127 次
- TaoStore: Overcoming Asynchronicity in Oblivious Data StorageCetin Sahin, Victor Zakhary, Amr El Abbadi, Huijia Lin 等S&P 2016 · 被引用 98 次
相关 Paper
- DISCO*: Distributed and SCalable Oblivious Joins and Oblivious PrimitivesApostolos Mavrogiannakis, Xian Wang, Ioannis Demertzis, Dimitrios Papadopoulos 等SOSP 2026
- Data Enclave: A Data-Centric Trusted Execution EnvironmentYuanchao Xu, James Pangia, Chencheng Ye, Yan Solihin 等HPCA 2024 · 被引用 8 次
- Leafblower: a Leakage Attack Against Tee-Based Encrypted DatabasesZachary Espiritu, Seny Kamara, Tarik Moataz, Valentin OgierS&P 2026 · 被引用 1 次
- Jodes: Efficient Oblivious Join in the Distributed SettingYilei Wang, Xiangdong Zeng, Sheng Wang, Feifei LiVLDB 2025 · 被引用 1 次
- EnigMap: External-Memory Oblivious Map for Secure EnclavesAfonso Tinoco, Sixiang Gao, Elaine ShiUSENIX Security 2023
