Leafblower: a Leakage Attack Against Tee-Based Encrypted Databases
Zachary Espiritu, Seny Kamara, Tarik Moataz, Valentin Ogier
摘要
Trusted execution environments (TEEs) have emerged as a common solution for database systems to provide encryption in use. Several encrypted databases (EDBs) have been deployed within TEEs using library operating system toolchains that transparently allow existing applications to run within TEEs without modification. This “lift-and-shift” paradigm greatly simplifies the design of EDBs but leaves open questions about the security of the resulting system. In this work, we propose a new leakage attack against TEEbased EDBs which use -trees in the multi-snapshot external memory model, a weaker adversary which only observes snapshots of the encrypted database index files after each operation. We show how to approximately order insertions by their inserted value by exploiting the “structural leakage” of the on-disk index format. Then, we leverage auxiliary information to recover the approximate plaintext values of insert operations with significant advantage over a naive adversary that makes guesses based on equivalent auxiliary information. Under optimal conditions-when the auxiliary is accurate and the domain is small-we achieve up to 96% exact recovery in experiments on real-world datasets which increases to 100% when scoped to later operations in the transcript. Our attack requires no injections and no information about read operations. While our work is primarily motivated by TEE-based encrypted databases, we demonstrate that our attack generalizes to other kinds of page-level encryption systems including encrypted storage engines and disaggregated database systems.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper50
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 被引用 649 次
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo 等S&P 2019 · 被引用 408 次
- Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGXWenhao Wang, Guoxing Chen, Xiaorui Pan, Yinqian Zhang 等CCS 2017 · 被引用 403 次
相关 Paper
- Building Enclave-Native Storage Engines for Practical Encrypted DatabasesYuanyuan Sun, Sheng Wang, Huorong Li, Feifei LiVLDB 2021 · 被引用 56 次
- Learning to Reconstruct: Statistical Learning Theory and Encrypted Database AttacksPaul Grubbs, Marie-Sarah Lacharité, Brice Minaud, Kenneth G. PatersonS&P 2019 · 被引用 146 次
- Snapshots of TEE-Based Encrypted Databases Leak Plaintext Histograms via DendrochronologyZachary EspirituCCS 2026
- Leakage-Abuse Attacks Against Structured Encryption for SQLAlexander Hoover, Ruth Ng, Daren Khu, Yao'an Li 等USENIX Security 2024 · 被引用 3 次
- Improved Reconstruction Attacks on Encrypted Data Using Range Query LeakageMarie-Sarah Lacharité, Brice Minaud, Kenneth G. PatersonS&P 2018 · 被引用 183 次
