...
首页> 外文期刊>Journal of computer security >HardlDX: Practical and secure index with SGX in a malicious environment
【24h】

HardlDX: Practical and secure index with SGX in a malicious environment

机译:HardlDX:SGX在恶意环境中的实用且安全的索引

获取原文
获取原文并翻译 | 示例
           

摘要

Software-based approaches for search over encrypted data are still either challenged by lack of proper, low-leakage encryption or slow performance. Existing hardware-based approaches do not scale well due to hardware limitations and software designs that are not specifically tailored to the hardware architecture, and are rarely well analyzed for their security (e.g. the impact of side channels). Additionally, existing hardware-based solutions often have a large code footprint in the trusted environment susceptible to software compromises. In this paper we present HardIDX: a hardware-based approach, leveraging Intel's SGX, for search over encrypted data. It implements only the security critical core, i.e., the search functionality, in the trusted environment and resorts to untrusted software for the remainder. HardIDX is deployable as a highly performant encrypted database index: it is logarithmic in the size of the index and searches are performed within a few milliseconds rather than seconds. We formally model and prove the security of our scheme showing that its leakage is equivalent to the best known searchable encryption schemes. Our implementation has a very small code and memory footprint yet still scales to virtually unlimited search index sizes, i.e., size is limited only by the general - non-secure - hardware resources.
机译:缺乏适当的低泄漏加密或性能低下仍然使基于软件的加密数据搜索方法面临挑战。由于硬件限制和未专门针对硬件体系结构设计的软件设计,基于硬件的现有方法无法很好地扩展,并且很少对其安全性(例如边信道的影响)进行很好的分析。此外,现有的基于硬件的解决方案通常在容易受到软件侵害的受信任环境中占用大量代码。在本文中,我们介绍了HardIDX:一种基于硬件的方法,利用Intel的SGX来搜索加密数据。它在受信任的环境中仅实现了安全性至关重要的核心,即搜索功能,其余部分则使用不受信任的软件。 HardIDX可部署为高性能的加密数据库索引:索引大小是对数的,并且搜索在几毫秒而不是几秒钟内完成。我们正式建模并证明了该方案的安全性,表明其泄漏与最著名的可搜索加密方案等效。我们的实现具有非常小的代码和内存占用量,但仍然可以扩展到几乎无限的搜索索引大小,即,大小仅受一般(非安全)硬件资源的限制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号