首页> 外文会议>ACM Conference on Computer and Communications Security >PrivateFS: A Parallel Oblivious File System
【24h】

PrivateFS: A Parallel Oblivious File System

机译:PRIVITIONFS:一个平行的绝密文件系统

获取原文

摘要

Privatefs is an oblivious file system that enables access to remote storage, while keeping both the file contents and client access patterns secret. Privatefs is based on a new parallel Oblivious RAM mechanism (PD-ORAM) - instead of waiting for the completion of all ongoing client-server transactions, client threads can now engage a server in parallel without loss of privacy. This critical piece is missing from existing Oblivious RAMs (ORAM), which can not allow multiple clients threads to operate simultaneously without revealing intra- and interquery correlations and thus incurring privacy leaks. And since ORAMs often require many communication rounds, this significantly and unnecessarily constrains throughput. The mechanisms introduced here eliminate this constraint, allowing overall throughput to be bound by server bandwidth only, and thus to increase by an order of magnitude. Further, new de-amortization techniques bring the worst case query cost in line with the average cost. Both of these results are shown to be fundamental to any ORAM. Extensions providing fork consistency against an actively malicious adversary are then presented. A high performance, fully functional PD-ORAM implementation was designed, built and analyzed. It performs multiple queries per second on a 1TB+ database across 50ms latency links, with unamortized, bound query latencies. Based on PD-ORAM, privatefs was built and deployed on Linux as a userspace file system.
机译:PrivateFS是一个不知情的文件系统,可以访问远程存储,同时保留文件内容和客户端访问模式秘密。 PrivateFS基于新的并行漏窃RAM机制(PD-ORAM) - 而不是等待完成所有持续的客户端 - 服务器事务,客户端线程现在可以在不丢失隐私的情况下并行地接合服务器。现有的漏窃rams(oram)缺少该关键块,其不能允许多个客户端线程同时运行,而不会显示内部和后续相关性,从而产生隐私泄漏。由于orams通常需要许多通信轮,这显着且不必要地限制了吞吐量。这里介绍的机制消除了该约束,允许仅通过服务器带宽绑定的整体吞吐量,从而增加了幅度级。此外,新的去摊销技术将符合平均成本的最坏情况查询成本。这两种结果都显示对任何oram的根本。然后展示提供票据对主动恶意对手的摊集一致性的扩展。设计,构建和分析了高性能,全功能PD-ORAM实现。它在1TB +数据库上每秒在50ms延迟链接上执行多个查询,其中包含未共享的绑定查询延迟。基于PD-ORAM,专用文件是在Linux上构建并部署为Userspace文件系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号