首页> 外文会议>IEEE/IFIP International Conference on Dependable Systems and Networks >EncDBDB: Searchable Encrypted, Fast, Compressed, In-Memory Database Using Enclaves
【24h】

EncDBDB: Searchable Encrypted, Fast, Compressed, In-Memory Database Using Enclaves

机译:encdbdb:搜索已加密,快速,压缩的内存内存数据库,使用concaves

获取原文

摘要

Data confidentiality is an important requirement for clients when outsourcing databases to the cloud. Trusted execution environments, such as Intel SGX, offer an efficient solution to this confidentiality problem. However, existing TEE-based solutions are not optimized for column-oriented, in-memory databases and pose impractical memory requirements on the enclave. We present EncDBDB, a novel approach for client-controlled encryption of a column-oriented, in-memory databases allowing range searches using an enclave. EncDBDB offers nine encrypted dictionaries, which provide different security, performance, and storage efficiency tradeoffs for the data. It is especially suited for complex, read-oriented, analytic queries as present, e.g., in data warehouses. The computational overhead compared to plaintext processing is within a millisecond even for databases with millions of entries and the leakage is limited. Compressed encrypted data requires less space than a corresponding plaintext column. Furthermore, EncDBDB’s enclave is very small reducing the potential for security-relevant implementation errors and side-channel leakages.
机译:数据机密性是将数据库到云端的客户端时对客户的重要要求。可信执行环境,例如Intel SGX,为此机密性问题提供有效的解决方案。但是,基于TEE的基于TEE的解决方案未针对面向列,内存数据库进行优化,并在该外区构成不切实际的存储器要求。我们呈现ENCDBDB,一种用于客户控制的临界加密的新方法,内存数据库允许使用飞地搜索范围。 ENCDBDB提供九个加密词典,为数据提供不同的安全性,性能和存储效率权衡。它特别适用于当前的复杂,读取的分析查询,例如数据仓库。与明文处理相比的计算开销也在毫秒内,即使对于具有数百万条目的数据库,泄漏有限。压缩的加密数据需要比对应的明文列更少的空间。此外,ENCDBDB的飞地非常小,减少了安全相关的实现错误和侧通道泄漏的潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号