{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,3]],"date-time":"2025-11-03T01:23:59Z","timestamp":1762133039483,"version":"build-2065373602"},"reference-count":97,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2024,12,14]],"date-time":"2024-12-14T00:00:00Z","timestamp":1734134400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,12,14]],"date-time":"2024-12-14T00:00:00Z","timestamp":1734134400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100001665","name":"Agence Nationale de la Recherche","doi-asserted-by":"publisher","award":["ANR-22-PECY-0002"],"award-info":[{"award-number":["ANR-22-PECY-0002"]}],"id":[{"id":"10.13039\/501100001665","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Distrib Parallel Databases"],"published-print":{"date-parts":[[2025,12]]},"DOI":"10.1007\/s10619-024-07449-1","type":"journal-article","created":{"date-parts":[[2024,12,13]],"date-time":"2024-12-13T23:32:46Z","timestamp":1734132766000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Enabling secure data-driven applications: an approach to personal data management using trusted execution environments"],"prefix":"10.1007","volume":"43","author":[{"given":"Robin","family":"Carpentier","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Iulian","family":"Sandu Popa","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nicolas","family":"Anciaux","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,12,14]]},"reference":[{"key":"7449_CR1","unstructured":"European Council: Regulation EU 2016\/679 of the European Parliament and of the Council (2016). http:\/\/data.europa.eu\/eli\/reg\/2016\/679\/2016-05-04 Accessed 2023-09-19"},{"key":"7449_CR2","unstructured":"Cozy: Cozy Cloud. https:\/\/cozy.io Accessed 2023-09-19"},{"key":"7449_CR3","unstructured":"Digi.me. https:\/\/digi.me Accessed 2022-09-27"},{"key":"7449_CR4","volume-title":"Solid: A Platform for Decentralized Social Applications Based on Linked Data","author":"AV Sambra","year":"2016","unstructured":"Sambra, A.V., Mansour, E., Hawke, S., Zereba, M., Greco, N., Ghanem, A., Zagidulin, D., Aboulnaga, A., Berners-Lee, T.: Solid: A Platform for Decentralized Social Applications Based on Linked Data. MIT CSAIL & Qatar Computing Research Institute, Technical report (2016)"},{"key":"7449_CR5","unstructured":"Solid. https:\/\/solidproject.org\/ Accessed 2023-09-25"},{"key":"7449_CR6","unstructured":"BitsAbout.me. https:\/\/bitsabout.me Accessed 2023-09-25"},{"key":"7449_CR7","doi-asserted-by":"crossref","unstructured":"Prifina. https:\/\/www.prifina.com Accessed 2023-09-25","DOI":"10.5965\/1984723825572024009"},{"key":"7449_CR8","unstructured":"mydex. https:\/\/mydex.org\/ Accessed 2023-09-25"},{"key":"7449_CR9","unstructured":"Nextcloud. https:\/\/nextcloud.com Accessed 2023-09-25"},{"key":"7449_CR10","doi-asserted-by":"crossref","unstructured":"MyDataMood. https:\/\/mydatamood.com Accessed 2023-09-25","DOI":"10.5965\/1984723825572024009"},{"key":"7449_CR11","unstructured":"MyData. https:\/\/mydata.org\/ Accessed 2023-09-25"},{"key":"7449_CR12","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1016\/j.is.2018.09.002","volume":"80","author":"N Anciaux","year":"2019","unstructured":"Anciaux, N., Bonnet, P., Bouganim, L., Nguyen, B., Pucheral, P., Sandu Popa, I., Scerri, G.: Personal data management systems: the security and functionality standpoint. Inf. Syst. 80, 13\u201335 (2019). https:\/\/doi.org\/10.1016\/j.is.2018.09.002","journal-title":"Inf. Syst."},{"key":"7449_CR13","doi-asserted-by":"publisher","unstructured":"Sabelfeld, A., Myers, A.C.: Language-based information-flow security 21(1), 5\u201319 (2003). https:\/\/doi.org\/10.1109\/JSAC.2002.806121","DOI":"10.1109\/JSAC.2002.806121"},{"key":"7449_CR14","doi-asserted-by":"publisher","unstructured":"Sun, M., Wei, T., Lui, J.C.S.: TaintART: A practical multi-level information-flow tracking system for android RunTime. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. CCS \u201916, pp. 331\u2013342 (2016). https:\/\/doi.org\/10.1145\/2976749.2978343","DOI":"10.1145\/2976749.2978343"},{"key":"7449_CR15","doi-asserted-by":"publisher","unstructured":"Myers, A.C.: JFlow: Practical mostly-static information flow control. In: Proceedings of the 26th ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages. POPL \u201999, pp. 228\u2013241 (1999). https:\/\/doi.org\/10.1145\/292540.292561","DOI":"10.1145\/292540.292561"},{"key":"7449_CR16","doi-asserted-by":"publisher","unstructured":"Dwork, C.: Differential privacy. In: Automata, Languages and Programming, pp. 1\u201312 (2006). https:\/\/doi.org\/10.1007\/11787006_1","DOI":"10.1007\/11787006_1"},{"key":"7449_CR17","unstructured":"Roy, I., Setty, S.T.V., Kilzer, A., Shmatikov, V., Witchel, E.: Airavat: Security and privacy for mapreduce. In: Proceedings of the 7th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2010, pp. 297\u2013312 (2010)"},{"issue":"4","key":"7449_CR18","doi-asserted-by":"publisher","first-page":"469","DOI":"10.1109\/TIT.1985.1057074","volume":"31","author":"T ElGamal","year":"1985","unstructured":"ElGamal, T.: A public key cryptosystem and a signature scheme based on discrete logarithms. IEEE Trans. Inf. Theory 31(4), 469\u2013472 (1985). https:\/\/doi.org\/10.1109\/TIT.1985.1057074","journal-title":"IEEE Trans. Inf. Theory"},{"key":"7449_CR19","doi-asserted-by":"crossref","unstructured":"Gentry, C.: A fully homomorphic encryption scheme. PhD thesis, Stanford University (2009)","DOI":"10.1145\/1536414.1536440"},{"key":"7449_CR20","unstructured":"Costan, V., Devadas, S.: Intel SGX Explained. Cryptology ePrint Archive (2016). https:\/\/eprint.iacr.org\/2016\/086"},{"key":"7449_CR21","doi-asserted-by":"publisher","DOI":"10.1145\/3291047","author":"S Pinto","year":"2019","unstructured":"Pinto, S., Santos, N.: Demystifying arm TrustZone: a comprehensive survey. ACM Comput. Surv. (2019). https:\/\/doi.org\/10.1145\/3291047","journal-title":"ACM Comput. Surv."},{"key":"7449_CR22","doi-asserted-by":"publisher","DOI":"10.1145\/3231594","author":"T Hunt","year":"2018","unstructured":"Hunt, T., Zhu, Z., Xu, Y., Peter, S., Witchel, E.: Ryoan: a distributed sandbox for untrusted computation on secret data. ACM Trans. Comput. Syst. (2018). https:\/\/doi.org\/10.1145\/3231594","journal-title":"ACM Trans. Comput. Syst."},{"key":"7449_CR23","unstructured":"Weiser, S., Mayr, L., Schwarz, M., Gruss, D.: SGXJail: Defeating enclave malware via confinement. In: 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2019), pp. 353\u2013366 (2019). https:\/\/www.usenix.org\/conference\/raid2019\/presentation\/weiser"},{"key":"7449_CR24","doi-asserted-by":"publisher","unstructured":"Carpentier, R., Sandu\u00a0Popa, I., Anciaux, N.: Local personal data processing with third party code and bounded leakage. In: Proceedings of the 11th International Conference on Data Science, Technology and Applications - DATA, pp. 520\u2013527 (2022). https:\/\/doi.org\/10.5220\/0011321900003269","DOI":"10.5220\/0011321900003269"},{"key":"7449_CR25","doi-asserted-by":"publisher","unstructured":"Carpentier, R., Sandu\u00a0Popa, I., Anciaux, N.: Data leakage mitigation of user-defined functions on secure personal data management systems. In: 34th International Conference on Scientific and Statistical Database Management. SSDBM 2022 (2022). https:\/\/doi.org\/10.1145\/3538712.3538741","DOI":"10.1145\/3538712.3538741"},{"key":"7449_CR26","doi-asserted-by":"publisher","unstructured":"Sabt, M., Achemlal, M., Bouabdallah, A.: Trusted execution environment: what it is, and what it is not. In: 2015 IEEE Trustcom\/BigDataSE\/ISPA, pp. 57\u201364 (2015). https:\/\/doi.org\/10.1109\/Trustcom.2015.357","DOI":"10.1109\/Trustcom.2015.357"},{"key":"7449_CR27","doi-asserted-by":"crossref","unstructured":"McKeen, F., Alexandrovich, I., Berenzon, A., Rozas, C.V., Shafi, H., Shanbhogue, V., Savagaonkar, U.R.: Innovative instructions and software model for isolated execution. Technical report, Intel Corporation (2013). https:\/\/perma.cc\/B93F-JSTY","DOI":"10.1145\/2487726.2488368"},{"key":"7449_CR28","unstructured":"ARM: Building a secure system using TrustZone technology. Technical report, ARM (2008). https:\/\/perma.cc\/WE2E-WV2A"},{"issue":"6","key":"7449_CR29","doi-asserted-by":"publisher","first-page":"54","DOI":"10.1109\/MSP.2016.124","volume":"14","author":"S Gueron","year":"2016","unstructured":"Gueron, S.: Memory encryption for general-purpose processors. IEEE Secur. Privacy 14(6), 54\u201362 (2016). https:\/\/doi.org\/10.1109\/MSP.2016.124","journal-title":"IEEE Secur. Privacy"},{"key":"7449_CR30","unstructured":"Anati, I., Gueron, S., Johnson, S.P., Scarlata, V.R.: Innovative technology for CPU based attestation and sealing. Technical report, Intel Corporation (2013). https:\/\/perma.cc\/CX5W-D56Z"},{"key":"7449_CR31","doi-asserted-by":"publisher","unstructured":"Brickell, E., Li, J.: Enhanced privacy ID from bilinear pairing for hardware authentication and attestation. In: 2010 IEEE Second International Conference on Social Computing, pp. 768\u2013775 (2010). https:\/\/doi.org\/10.1504\/IJIPSI.2011.043729","DOI":"10.1504\/IJIPSI.2011.043729"},{"key":"7449_CR32","unstructured":"Lee, J., Jang, J., Jang, Y., Kwak, N., Choi, Y., Choi, C., Kim, T., Peinado, M., Kang, B.B.: Hacking in darkness: return-oriented programming against secure enclaves. In: 26th USENIX Security Symposium (USENIX Security 17), pp. 523\u2013539 (2017). https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/lee-jaehyuk"},{"key":"7449_CR33","doi-asserted-by":"publisher","unstructured":"Schwarz, M., Weiser, S., Gruss, D.: Practical enclave malware with intel SGX. In: Detection of Intrusions and Malware, and Vulnerability Assessment, pp. 177\u2013196 (2019). https:\/\/doi.org\/10.1007\/978-3-030-22038-9_9","DOI":"10.1007\/978-3-030-22038-9_9"},{"key":"7449_CR34","doi-asserted-by":"publisher","unstructured":"Goltzsche, D., Nieke, M., Knauth, T., Kapitza, R.: AccTEE: A WebAssembly-based two-way sandbox for trusted resource accounting. In: Proceedings of the 20th International Middleware Conference. Middleware \u201919, pp. 123\u2013135 (2019).https:\/\/doi.org\/10.1145\/3361525.3361541","DOI":"10.1145\/3361525.3361541"},{"key":"7449_CR35","doi-asserted-by":"publisher","unstructured":"Park, J., Kang, S., Lee, S., Kim, T., Park, J., Kwon, Y., Huh, J.: Stockade: Hardware Hardening for Distributed Trusted Sandboxes. arXiv (2021). https:\/\/doi.org\/10.48550\/ARXIV.2108.13922","DOI":"10.48550\/ARXIV.2108.13922"},{"issue":"4","key":"7449_CR36","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3532862","volume":"25","author":"J Cui","year":"2022","unstructured":"Cui, J., Shinde, S., Sen, S., Saxena, P., Yuan, P.: Dynamic binary translation for SGX enclaves. ACM Trans. Priv. Secur. 25(4), 1\u201340 (2022). https:\/\/doi.org\/10.1145\/3532862","journal-title":"ACM Trans. Priv. Secur."},{"key":"7449_CR37","doi-asserted-by":"publisher","unstructured":"Carpentier, R., Sandu\u00a0Popa, I., Anciaux, N.: Poster: reducing data leakage on personal data management systems. In: 2021 IEEE European Symposium on Security and Privacy (EuroS &P), pp. 716\u2013718 (2021). https:\/\/doi.org\/10.1109\/EuroSP51992.2021.00057","DOI":"10.1109\/EuroSP51992.2021.00057"},{"key":"7449_CR38","doi-asserted-by":"publisher","unstructured":"Brenner, S., Behlendorf, M., Kapitza, R.: Trusted execution, and the impact of security on performance. In: Proceedings of the 3rd Workshop on System Software for Trusted Execution. SysTEX \u201918, pp. 28\u201333 (2018). https:\/\/doi.org\/10.1145\/3268935.3268943","DOI":"10.1145\/3268935.3268943"},{"key":"7449_CR39","doi-asserted-by":"publisher","unstructured":"Gjerdrum, A.T., Pettersen, R., Johansen, H.D., Johansen, D.: Performance of trusted computing in cloud infrastructures with intel SGX. In: Proceedings of the 7th International Conference on Cloud Computing and Services Science, CLOSER, pp. 668\u2013675 (2017). https:\/\/doi.org\/10.1007\/978-3-319-94959-8_1","DOI":"10.1007\/978-3-319-94959-8_1"},{"key":"7449_CR40","doi-asserted-by":"publisher","unstructured":"Carpentier, R., Thiant, F., Sandu\u00a0Popa, I., Anciaux, N., Bouganim, L.: an extensive and secure personal data management system using SGX. In: Proceedings of the 25th International Conference on Extending Database Technology, EDBT (2022).https:\/\/doi.org\/10.48786\/edbt.2022.53","DOI":"10.48786\/edbt.2022.53"},{"key":"7449_CR41","unstructured":"Microsoft: Open Enclave SDK. https:\/\/openenclave.io Accessed 2023-09-25"},{"key":"7449_CR42","unstructured":"TrustedFirmware: Mbed TLS. https:\/\/tls.mbed.org\/ Accessed 2023-09-25"},{"key":"7449_CR43","unstructured":"Georges Hebrail, Alice Berard: Individual household electric power consumption Data Set (2012). https:\/\/archive.ics.uci.edu\/ml\/datasets\/individual+household+electric+power+consumption Accessed 2023-09-25"},{"key":"7449_CR44","unstructured":"Microsoft Research Asia: GeoLife GPS Trajectories (2016). https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=52367 Accessed 2023-09-25"},{"key":"7449_CR45","unstructured":"Intel: 3rd Gen Intel Xeon Scalable Processors Brief (2021). https:\/\/www.intel.com\/content\/www\/us\/en\/products\/docs\/processors\/xeon\/3rd-gen-xeon-scalable-processors-brief.html Accessed 2023-09-25"},{"key":"7449_CR46","unstructured":"nPerf: Barom\u00e8tre des connexions internet fixes en france m\u00e9tropolitaine. Technical report, nPerf (2020). https:\/\/perma.cc\/DP8V-5ABT"},{"key":"7449_CR47","doi-asserted-by":"publisher","unstructured":"Hasan, A., Riley, R., Ponomarev, D.: Port or shim? Stress testing application performance on intel SGX. In: 2020 IEEE International Symposium on Workload Characterization (IISWC), pp. 123\u2013133 (2020). https:\/\/doi.org\/10.1109\/IISWC50251.2020.00021","DOI":"10.1109\/IISWC50251.2020.00021"},{"key":"7449_CR48","unstructured":"Personium. https:\/\/personium.io Accessed 2023-09-25"},{"issue":"7","key":"7449_CR49","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1371\/journal.pone.0098790","volume":"9","author":"Y-A Montjoye","year":"2014","unstructured":"Montjoye, Y.-A., Shmueli, E., Wang, S.S., Pentland, A.S.: OpenPDS: protecting the privacy of metadata through safe answers. PLoS ONE 9(7), 1\u20139 (2014). https:\/\/doi.org\/10.1371\/journal.pone.0098790","journal-title":"PLoS ONE"},{"key":"7449_CR50","doi-asserted-by":"publisher","unstructured":"Chaudhry, A., Crowcroft, J., Howard, H., Madhavapeddy, A., Mortier, R., Haddadi, H., McAuley, D.: Personal Data: Thinking Inside the Box. Aarhus Series on Human Centered Computing 1(1) (2015) https:\/\/doi.org\/10.7146\/aahcc.v1i1.21312","DOI":"10.7146\/aahcc.v1i1.21312"},{"key":"7449_CR51","doi-asserted-by":"publisher","unstructured":"Novak, E., Aung, P.T., Do, T.: VPN+ towards detection and remediation of information leakage on smartphones. In: 2020 21st IEEE International Conference on Mobile Data Management (MDM), pp. 39\u201348 (2020). https:\/\/doi.org\/10.1109\/MDM48529.2020.00025","DOI":"10.1109\/MDM48529.2020.00025"},{"key":"7449_CR52","doi-asserted-by":"publisher","unstructured":"Ren, J., Rao, A., Lindorfer, M., Legout, A., Choffnes, D.: ReCon: Revealing and controlling PII leaks in mobile network traffic. In: Proceedings of the 14th Annual International Conference on Mobile Systems, Applications, and Services. MobiSys \u201916, pp. 361\u2013374 (2016). https:\/\/doi.org\/10.1145\/2906388.2906392","DOI":"10.1145\/2906388.2906392"},{"key":"7449_CR53","doi-asserted-by":"crossref","unstructured":"Anciaux, N., Bouganim, L., Pucheral, P.: Data confidentiality: to which extent cryptography and secured hardware can help. Annals of Telecommunications-annales des t\u00e9l\u00e9communications 61(3-4) (2006)","DOI":"10.1007\/BF03219909"},{"key":"7449_CR54","doi-asserted-by":"publisher","unstructured":"Anciaux, N., Bouganim, L., Guo, Y., Pucheral, P., Vandewalle, J.-J., Yin, S.: Pluggable personal data servers. In: Proceedings of the 2010 ACM SIGMOD International Conference on Management of Data. SIGMOD \u201910, pp. 1235\u20131238 (2010). https:\/\/doi.org\/10.1145\/1807167.1807328","DOI":"10.1145\/1807167.1807328"},{"key":"7449_CR55","unstructured":"Anciaux, N., Bonnet, P., Bouganim, L., Nguyen, B., Sandu\u00a0Popa, I., Pucheral, P.: Trusted cells: a sea change for personal data services. In: Proceedings of the 6th Biennal Conference on Innovative Database Research (CIDR) (2013)"},{"issue":"3","key":"7449_CR56","first-page":"49","volume":"30","author":"N Anciaux","year":"2007","unstructured":"Anciaux, N., Bouganim, L., Pucheral, P.: Future trends in secure chip data management. Bull. Tech. Committee Data Eng. 30(3), 49\u201357 (2007)","journal-title":"Bull. Tech. Committee Data Eng."},{"issue":"3","key":"7449_CR57","doi-asserted-by":"publisher","first-page":"2129","DOI":"10.1007\/s10639-019-10043-z","volume":"25","author":"S Mitra","year":"2020","unstructured":"Mitra, S., Gupta, S.: Mobile learning under personal cloud with a virtualization framework for outcome based education. Educ. Inf. Technol. 25(3), 2129\u20132156 (2020). https:\/\/doi.org\/10.1007\/s10639-019-10043-z","journal-title":"Educ. Inf. Technol."},{"issue":"1","key":"7449_CR58","volume":"2008","author":"N Anciaux","year":"2008","unstructured":"Anciaux, N., Berthelot, M., Braconnier, L., Bouganim, L., Blache, M., Gardarin, G., Kesmarszky, P., Lartigue, S., Navarre, J.-F., Pucheral, P., et al.: A tamper-resistant and portable healthcare folder. Int. J. Telemed. Appl. 2008(1), 763534 (2008)","journal-title":"Int. J. Telemed. Appl."},{"key":"7449_CR59","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2869848","author":"M Akter","year":"2018","unstructured":"Akter, M., Gani, A., Rahman, M.O., Hassan, M.M., Almogren, A., Ahmad, S.: Performance analysis of personal cloud storage services for mobile multimedia health record management. IEEE Access (2018). https:\/\/doi.org\/10.1109\/ACCESS.2018.2869848","journal-title":"IEEE Access"},{"key":"7449_CR60","doi-asserted-by":"publisher","DOI":"10.1016\/j.is.2017.09.003","author":"S Lallali","year":"2017","unstructured":"Lallali, S., Anciaux, N., Popa, I.S., Pucheral, P.: Supporting secure keyword search in the personal cloud. Inf. Syst. (2017). https:\/\/doi.org\/10.1016\/j.is.2017.09.003","journal-title":"Inf. Syst."},{"issue":"9","key":"7449_CR61","doi-asserted-by":"publisher","first-page":"910","DOI":"10.14778\/2777598.2777600","volume":"8","author":"N Anciaux","year":"2015","unstructured":"Anciaux, N., Lallali, S., Sandu Popa, I., Pucheral, P.: A scalable search engine for mass storage smart objects. Proc. VLDB Endow. 8(9), 910\u2013921 (2015). https:\/\/doi.org\/10.14778\/2777598.2777600","journal-title":"Proc. VLDB Endow."},{"key":"7449_CR62","doi-asserted-by":"publisher","unstructured":"Perera, C., Wakenshaw, S., Baarslag, T., Haddadi, H., Bandara, A., Mortier, R., Crabtree, A., Ng, I., McAuley, D., Crowcroft, J.: Valorising the IoT databox: creating value for everyone (2016) https:\/\/doi.org\/10.48550\/ARXIV.1609.03312","DOI":"10.48550\/ARXIV.1609.03312"},{"key":"7449_CR63","doi-asserted-by":"publisher","unstructured":"Meurisch, C., Bayrak, B., M\u00fchlh\u00e4user, M.: Privacy-preserving AI services through data decentralization. In: Proceedings of The Web Conference 2020. WWW \u201920, pp. 190\u2013200 (2020). https:\/\/doi.org\/10.1145\/3366423.3380106","DOI":"10.1145\/3366423.3380106"},{"key":"7449_CR64","unstructured":"Microsoft: Azure SQL - Always encrypted with secure enclaves (2019). https:\/\/docs.microsoft.com\/en-us\/sql\/relational-databases\/security\/encryption\/always-encrypted-enclaves Accessed 2021-11-04"},{"key":"7449_CR65","doi-asserted-by":"publisher","unstructured":"Priebe, C., Vaswani, K., Costa, M.: EnclaveDB: a secure database using SGX. In: 2018 IEEE Symposium on Security and Privacy (SP), pp. 264\u2013278 (2018). https:\/\/doi.org\/10.1109\/SP.2018.00025","DOI":"10.1109\/SP.2018.00025"},{"key":"7449_CR66","doi-asserted-by":"publisher","unstructured":"Zhou, W., Cai, Y., Peng, Y., Wang, S., Ma, K., Li, F.: VeriDB: an SGX-based verifiable database. In: Proceedings of the 2021 International Conference on Management Of Data. SIGMOD\/PODS \u201921, pp. 2182\u20132194 (2021). https:\/\/doi.org\/10.1145\/3448016.3457308","DOI":"10.1145\/3448016.3457308"},{"key":"7449_CR67","doi-asserted-by":"publisher","DOI":"10.1016\/j.is.2020.101681","author":"Z Han","year":"2021","unstructured":"Han, Z., Hu, H.: ProDB: a memory-secure database using hardware enclave and practical oblivious RAM. Inf. Syst. (2021). https:\/\/doi.org\/10.1016\/j.is.2020.101681","journal-title":"Inf. Syst."},{"key":"7449_CR68","unstructured":"Edgeless Systems: EdgelessDB (2021). https:\/\/www.edgeless.systems\/products\/edgelessdb\/ Accessed 2021-11-02"},{"issue":"5","key":"7449_CR69","doi-asserted-by":"publisher","first-page":"666","DOI":"10.1109\/TC.2019.2963303","volume":"69","author":"Y Wang","year":"2019","unstructured":"Wang, Y., Shen, Y., Su, C., Ma, J., Liu, L., Dong, X.: Cryptsqlite: Sqlite with high data security. IEEE Trans. Comput. 69(5), 666\u2013678 (2019). https:\/\/doi.org\/10.1109\/TC.2019.2963303","journal-title":"IEEE Trans. Comput."},{"key":"7449_CR70","doi-asserted-by":"publisher","unstructured":"Unnibhavi, H., Cerdeira, D., Barbalace, A., Santos, N., Bhatotia, P.: Secure and policy-compliant query processing on heterogeneous computational storage architectures. In: ACM SIGMOD\/PODS International Conference on Management of Data 2022 (2022). https:\/\/doi.org\/10.1145\/3514221.3517913","DOI":"10.1145\/3514221.3517913"},{"key":"7449_CR71","doi-asserted-by":"publisher","unstructured":"Godfrey, M., Mayr, T., Seshadri, P., Eicken, T.: Secure and portable database extensibility. In: Proceedings of the 1998 ACM SIGMOD International Conference on Management of Data. SIGMOD \u201998, pp. 390\u2013401. https:\/\/doi.org\/10.1145\/276304.276339","DOI":"10.1145\/276304.276339"},{"key":"7449_CR72","doi-asserted-by":"publisher","unstructured":"Wanninger, N.C., Bowden, J.J., Shetty, K., Garg, A., Hale, K.C.: Isolating functions at the hardware limit with virtines. In: Proceedings of the Seventeenth European Conference on Computer Systems. EuroSys \u201922, pp. 644\u2013662. https:\/\/doi.org\/10.1145\/3492321.3519553","DOI":"10.1145\/3492321.3519553"},{"key":"7449_CR73","unstructured":"Snowflake: Secure UDF (2019). https:\/\/docs.snowflake.com\/en\/sql-reference\/udf-secure.html Accessed 2021-11-04"},{"key":"7449_CR74","doi-asserted-by":"publisher","unstructured":"Herzberg, B., Cohen, Y.: Secure data sharing with snowflake. In: Snowflake Security, pp. 163\u2013175 (2022). https:\/\/doi.org\/10.1007\/978-1-4842-7389-0_8","DOI":"10.1007\/978-1-4842-7389-0_8"},{"key":"7449_CR75","unstructured":"Google: Google BigQuery - Authorized Functions (2011). https:\/\/cloud.google.com\/bigquery\/docs\/authorized-functions Accessed 2021-11-04"},{"key":"7449_CR76","doi-asserted-by":"publisher","unstructured":"Brenner, S., Kapitza, R.: Trust more, serverless. In: Proceedings of the 12th ACM International Conference on Systems and Storage. SYSTOR \u201919, pp. 33\u201343 (2019).https:\/\/doi.org\/10.1145\/3319647.3325825","DOI":"10.1145\/3319647.3325825"},{"key":"7449_CR77","doi-asserted-by":"publisher","unstructured":"Trach, B., Oleksenko, O., Gregor, F., Bhatotia, P., Fetzer, C.: Clemmys: Towards secure remote execution in FaaS. In: Proceedings of the 12th ACM International Conference on Systems and Storage. SYSTOR \u201919, pp. 44\u201354 (2019). https:\/\/doi.org\/10.1145\/3319647.3325835","DOI":"10.1145\/3319647.3325835"},{"key":"7449_CR78","doi-asserted-by":"publisher","unstructured":"Zhang, R., Zhang, N., Moini, A., Lou, W., Hou, Y.T.: PrivacyScope: Automatic analysis of private data leakage in TEE-protected applications. In: 2020 IEEE 40th International Conference on Distributed Computing Systems (ICDCS), pp. 34\u201344 (2020). https:\/\/doi.org\/10.1109\/ICDCS47774.2020.00013","DOI":"10.1109\/ICDCS47774.2020.00013"},{"key":"7449_CR79","doi-asserted-by":"publisher","DOI":"10.1145\/2619091","author":"W Enck","year":"2014","unstructured":"Enck, W., Gilbert, P., Han, S., Tendulkar, V., Chun, B.-G., Cox, L.P., Jung, J., McDaniel, P., Sheth, A.N.: TaintDroid: an information-flow tracking system for realtime privacy monitoring on smartphones. ACM Trans. Comput. Syst. (2014). https:\/\/doi.org\/10.1145\/2619091","journal-title":"ACM Trans. Comput. Syst."},{"key":"7449_CR80","doi-asserted-by":"publisher","unstructured":"Zavalyshyn, I., Duarte, N.O., Santos, N.: HomePad: a privacy-aware smart hub for home environments. In: 2018 IEEE\/ACM Symposium on Edge Computing (SEC), pp. 58\u201373 (2018). https:\/\/doi.org\/10.1109\/SEC.2018.00012","DOI":"10.1109\/SEC.2018.00012"},{"key":"7449_CR81","unstructured":"Lee, S., Shih, M.-W., Gera, P., Kim, T., Kim, H., Peinado, M.: Inferring fine-grained control flow inside SGX enclaves with branch shadowing. In: 26th USENIX Security Symposium (USENIX Security 17), pp. 557\u2013574. https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/lee-sangho"},{"key":"7449_CR82","unstructured":"Bulck, J.V., Minkin, M., Weisse, O., Genkin, D., Kasikci, B., Piessens, F., Silberstein, M., Wenisch, T.F., Yarom, Y., Strackx, R.: Foreshadow: Extracting the keys to the intel SGX kingdom with transient out-of-order execution. In: 27th USENIX Security Symposium (USENIX Security 18), pp. 991\u20131008. https:\/\/www.usenix.org\/conference\/usenixsecurity18\/presentation\/bulck"},{"key":"7449_CR83","doi-asserted-by":"publisher","unstructured":"Schaik, S., Minkin, M., Kwong, A., Genkin, D., Yarom, Y.: CacheOut: Leaking data on intel CPUs via cache evictions. In: 2021 IEEE Symposium on Security and Privacy (SP), pp. 339\u2013354 (2021). https:\/\/doi.org\/10.1109\/SP40001.2021.00064","DOI":"10.1109\/SP40001.2021.00064"},{"key":"7449_CR84","unstructured":"Schaik, S., Kwong, A., Genkin, D., Yarom, Y.: SGAxe: How SGX Fails in Practice (2020). https:\/\/sgaxe.com\/ Accessed 2024-07-15"},{"key":"7449_CR85","doi-asserted-by":"publisher","unstructured":"Schwarz, M., Weiser, S., Gruss, D., Maurice, C., Mangard, S.: Malware guard extension: using SGX to conceal cache attacks. In: Detection of Intrusions and Malware, and Vulnerability Assessment, pp. 3\u201324. https:\/\/doi.org\/10.1007\/978-3-319-60876-1_1","DOI":"10.1007\/978-3-319-60876-1_1"},{"key":"7449_CR86","unstructured":"Brasser, F., M\u00fcller, U., Dmitrienko, A., Kostiainen, K., Capkun, S., Sadeghi, A.-R.: Software grand exposure: SGX cache attacks are practical. In: 11th USENIX Workshop on Offensive Technologies (WOOT 17). https:\/\/www.usenix.org\/conference\/woot17\/workshop-program\/presentation\/brasser"},{"key":"7449_CR87","doi-asserted-by":"publisher","unstructured":"G\u00f6tzfried, J., Eckert, M., Schinzel, S., M\u00fcller, T.: Cache attacks on intel SGX. In: Proceedings of the 10th European Workshop on Systems Security. EuroSec\u201917 (2017).https:\/\/doi.org\/10.1145\/3065913.3065915","DOI":"10.1145\/3065913.3065915"},{"key":"7449_CR88","unstructured":"Bulck, J.V., Weichbrodt, N., Kapitza, R., Piessens, F., Strackx, R.: Telling your secrets without page faults: stealthy page table-based attacks on enclaved execution. In: 26th USENIX Security Symposium (USENIX Security 17), pp. 1041\u20131056 (2017). https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/van-bulck"},{"key":"7449_CR89","doi-asserted-by":"publisher","unstructured":"Xu, Y., Cui, W., Peinado, M.: Controlled-channel attacks: deterministic side channels for untrusted operating systems. In: 2015 IEEE Symposium on Security and Privacy, pp. 640\u2013656. https:\/\/doi.org\/10.1109\/SP.2015.45","DOI":"10.1109\/SP.2015.45"},{"key":"7449_CR90","unstructured":"Gruss, D., Lettner, J., Schuster, F., Ohrimenko, O., Haller, I., Costa, M.: Strong and efficient cache side-channel protection using hardware transactional memory. In: 26th USENIX Security Symposium (USENIX Security 17), pp. 217\u2013233 (2017). https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/gruss"},{"key":"7449_CR91","doi-asserted-by":"publisher","unstructured":"Shih, M.-W., Lee, S., Kim, T., Peinado, M.: T-SGX: Eradicating controlled-channel attacks against enclave programs. In: Proceedings of the 2017 Annual Network and Distributed System Security Symposium (NDSS). https:\/\/doi.org\/10.14722\/ndss.2017.23193","DOI":"10.14722\/ndss.2017.23193"},{"key":"7449_CR92","doi-asserted-by":"publisher","unstructured":"Chen, G., Wang, W., Chen, T., Chen, S., Zhang, Y., Wang, X., Lai, T., Lin, D.: Racing in hyperspace: closing hyper-threading side channels on SGX with contrived data races. In: 2018 IEEE Symposium on Security and Privacy (SP), pp. 178\u2013194 (2018). https:\/\/doi.org\/10.1109\/SP.2018.00024","DOI":"10.1109\/SP.2018.00024"},{"key":"7449_CR93","unstructured":"Oleksenko, O., Trach, B., Krahn, R., Silberstein, M., Fetzer, C.: Varys: protecting SGX enclaves from practical side-channel attacks. In: 2018 USENIX Annual Technical Conference (USENIX ATC 18), Boston, MA, pp. 227\u2013240 (2018). https:\/\/www.usenix.org\/conference\/atc18\/presentation\/oleksenko"},{"key":"7449_CR94","doi-asserted-by":"publisher","unstructured":"Chen, S., Zhang, X., Reiter, M.K., Zhang, Y.: Detecting privileged side-channel attacks in shielded execution with d\u00e9j\u00e1 vu. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security. ASIA CCS \u201917, pp. 7\u201318. https:\/\/doi.org\/10.1145\/3052973.3053007","DOI":"10.1145\/3052973.3053007"},{"key":"7449_CR95","doi-asserted-by":"publisher","unstructured":"Sasy, S., Gorbunov, S., Fletcher, C.W.: Zerotrace : Oblivious memory primitives from intel SGX. In: 25th Annual Network and Distributed System Security Symposium, NDSS (2018). https:\/\/doi.org\/10.14722\/ndss.2018.23239","DOI":"10.14722\/ndss.2018.23239"},{"issue":"2","key":"7449_CR96","doi-asserted-by":"publisher","first-page":"169","DOI":"10.14778\/3364324.3364331","volume":"13","author":"S Eskandarian","year":"2019","unstructured":"Eskandarian, S., Zaharia, M.: ObliDB: oblivious query processing for secure databases. Proc. VLDB Endow. 13(2), 169\u2013183 (2019). https:\/\/doi.org\/10.14778\/3364324.3364331","journal-title":"Proc. VLDB Endow."},{"issue":"9","key":"7449_CR97","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3652597","volume":"56","author":"P-C Cheng","year":"2024","unstructured":"Cheng, P.-C., Ozga, W., Valdez, E., Ahmed, S., Gu, Z., Jamjoom, H., Franke, H., Bottomley, J.: Intel tdx demystified: a top-down approach. ACM Comput. Surv. 56(9), 1\u201333 (2024). https:\/\/doi.org\/10.1145\/3652597","journal-title":"ACM Comput. Surv."}],"container-title":["Distributed and Parallel Databases"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10619-024-07449-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10619-024-07449-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10619-024-07449-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,3]],"date-time":"2025-11-03T01:19:18Z","timestamp":1762132758000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10619-024-07449-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,14]]},"references-count":97,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,12]]}},"alternative-id":["7449"],"URL":"https:\/\/doi.org\/10.1007\/s10619-024-07449-1","relation":{},"ISSN":["0926-8782","1573-7578"],"issn-type":[{"type":"print","value":"0926-8782"},{"type":"electronic","value":"1573-7578"}],"subject":[],"published":{"date-parts":[[2024,12,14]]},"assertion":[{"value":"8 November 2024","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"14 December 2024","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no Conflict of interest to declare that are relevant to the content of this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"5"}}