首页> 外文期刊>Computer-Aided Design of Integrated Circuits and Systems, IEEE Transactions on >The HEROIC Framework: Encrypted Computation Without Shared Keys
【24h】

The HEROIC Framework: Encrypted Computation Without Shared Keys

机译:HEROIC框架:不带共享密钥的加密计算

获取原文
获取原文并翻译 | 示例
       

摘要

Outsourcing computation to the cloud has recently become a very attractive option for enterprises and consumers, due to mostly reduced cost and extensive scalability. At the same time, however, concerns about the privacy of the data entrusted to cloud providers keeps rising. To address these concerns and thwart potential attackers, cloud providers today resort to numerous security controls as well as data encryption. Since the actual computation is still unencrypted inside cloud microprocessor chips, it is only a matter of time until new attacks and side channels are devised to leak sensitive information. To address the challenge of securing general-purpose computation inside microprocessor chips, we propose a novel computer architecture, and present a complete framework for general-purpose encrypted computation without shared keys, enabling secure data processing. This new architecture, called homomophically encrypted one instruction computation, contrary to the previous work in the area does not require a secret key installed inside the microprocessor chip. Instead, it leverages the powerful properties of homomorphic encryption combined with the simplicity of one instruction set computing. The proposed framework introduces: 1) a RTL implementation for reconfigurable hardware and 2) a ready-to-deploy virtual machine, which can be readily ported to existing server processor architectures.
机译:由于大大降低了成本和广泛的可扩展性,将计算外包到云近来已成为企业和消费者非常有吸引力的选择。但是,与此同时,对委托给云提供商的数据的隐私性的关注也在增加。为了解决这些问题并阻止潜在的攻击者,如今的云提供商采用了许多安全控制以及数据加密。由于实际的计算仍未在云微处理器芯片内部进行加密,因此设计新的攻击和旁通道泄漏敏感信息只是时间问题。为了解决在微处理器芯片内部保护通用计算的挑战,我们提出了一种新颖的计算机体系结构,并提出了一种无需共享密钥即可用于通用加密计算的完整框架,从而实现了安全的数据处理。与以前在该领域的工作相反,这种称为同态加密的单指令计算的新体系结构不需要在微处理器芯片内安装密钥。相反,它利用了同态加密的强大功能以及一个指令集计算的简单性。拟议的框架引入:1)用于可重配置硬件的RTL实现; 2)准备部署的虚拟机,可以很容易地移植到现有的服务器处理器体系结构上。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号