{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,2,13]],"date-time":"2024-02-13T13:01:27Z","timestamp":1707829287236},"reference-count":36,"publisher":"Privacy Enhancing Technologies Symposium Advisory Board","issue":"1","license":[{"start":{"date-parts":[[2020,11,9]],"date-time":"2020-11-09T00:00:00Z","timestamp":1604880000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,1,1]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Intel SGX has been a popular trusted execution environment (TEE) for protecting the integrity and confidentiality of applications running on untrusted platforms such as cloud. However, the access patterns of SGX-based programs can still be observed by adversaries, which may leak important information for successful attacks. Researchers have been experimenting with Oblivious RAM (ORAM) to address the privacy of access patterns. ORAM is a powerful low-level primitive that provides application-agnostic protection for any I\/O operations, however, at a high cost. We find that some application-specific access patterns, such as sequential block I\/O, do not provide additional information to adversaries. Others, such as sorting, can be replaced with specific oblivious algorithms that are more efficient than ORAM. The challenge is that developers may need to look into all the details of application-specific access patterns to design suitable solutions, which is time-consuming and error-prone. In this paper, we present the lightweight SGX based MapReduce (SGX-MR) approach that regulates the dataflow of data-intensive SGX applications for easier application-level access-pattern analysis and protection. It uses the MapReduce framework to cover a large class of data-intensive applications, and the entire framework can be implemented with a small memory footprint. With this framework, we have examined the stages of data processing, identified the access patterns that need protection, and designed corresponding efficient protection methods. Our experiments show that SGX-MR based applications are much more efficient than the ORAM-based implementations.<\/jats:p>","DOI":"10.2478\/popets-2021-0002","type":"journal-article","created":{"date-parts":[[2020,12,22]],"date-time":"2020-12-22T11:47:05Z","timestamp":1608637625000},"page":"5-20","source":"Crossref","is-referenced-by-count":5,"title":["SGX-MR: Regulating Dataflows for Protecting Access Patterns of Data-Intensive SGX Applications"],"prefix":"10.56553","volume":"2021","author":[{"given":"A K M Mubashwir","family":"Alam","sequence":"first","affiliation":[{"name":"Marquette University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sagar","family":"Sharma","sequence":"additional","affiliation":[{"name":"HP Inc."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Keke","family":"Chen","sequence":"additional","affiliation":[{"name":"Marquette University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"35752","published-online":{"date-parts":[[2020,11,9]]},"reference":[{"key":"2022061123201034254_j_popets-2021-0002_ref_001_w2aab3b7b4b1b6b1ab1ab1Aa","doi-asserted-by":"crossref","unstructured":"[1] A. Ahmad, K. Kim, M. I. Sarfaraz, and B. Lee. Obliviate: A data oblivious file system for Intel SGX. In the Network and Distributed System Security Symposium, 2018.10.14722\/ndss.2018.23284","DOI":"10.14722\/ndss.2018.23284"},{"key":"2022061123201034254_j_popets-2021-0002_ref_002_w2aab3b7b4b1b6b1ab1ab2Aa","unstructured":"[2] S. Arnautov, B. Trach, F. Gregor, T. Knauth, A. Martin, C. Priebe, J. Lind, D. Muthukumaran, D. O\u2019Keeffe, M. L. Stillwell, D. Goltzsche, D. Eyers, R. Kapitza, P. Pietzuch, and C. Fetzer. Scone: Secure linux containers with intel sgx. In Proceedings of the 12th USENIX Conference on Operating Systems Design and Implementation, OSDI\u201916, pages 689\u2013703, Berkeley, CA, USA, 2016. USENIX Association."},{"key":"2022061123201034254_j_popets-2021-0002_ref_003_w2aab3b7b4b1b6b1ab1ab3Aa","doi-asserted-by":"crossref","unstructured":"[3] K. E. Batcher. Sorting networks and their applications. In Proceedings of the April 30\u2013May 2, 1968, Spring Joint Computer Conference, AFIPS \u201968 (Spring), pages 307\u2013314, New York, NY, USA, 1968. ACM.10.1145\/1468075.1468121","DOI":"10.1145\/1468075.1468121"},{"key":"2022061123201034254_j_popets-2021-0002_ref_004_w2aab3b7b4b1b6b1ab1ab4Aa","doi-asserted-by":"crossref","unstructured":"[4] Z. Brakerski and V. Vaikuntanathan. Fully homomorphic encryption from ring-lwe and security for key dependent messages. In Proceedings of the 31st Annual Conference on Advances in Cryptology, CRYPTO\u201911, pages 505\u2013524, Berlin, Heidelberg, 2011. Springer-Verlag.10.1007\/978-3-642-22792-9_29","DOI":"10.1007\/978-3-642-22792-9_29"},{"key":"2022061123201034254_j_popets-2021-0002_ref_005_w2aab3b7b4b1b6b1ab1ab5Aa","doi-asserted-by":"crossref","unstructured":"[5] D. Cash, P. Grubbs, J. Perry, and T. Ristenpart. Leakage-abuse attacks against searchable encryption. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, CCS \u201915, page 668\u2013679, New York, NY, USA, 2015. Association for Computing Machinery.10.1145\/2810103.2813700","DOI":"10.1145\/2810103.2813700"},{"key":"2022061123201034254_j_popets-2021-0002_ref_006_w2aab3b7b4b1b6b1ab1ab6Aa","doi-asserted-by":"crossref","unstructured":"[6] C.-T. Chu, S. K. Kim, Y.-A. Lin, Y. Yu, G. Bradski, and A. Y. Ng. Map-reduce for machine learning on multicore. In Proceedings Of Neural Information Processing Systems (NIPS), 2006.","DOI":"10.7551\/mitpress\/7503.003.0040"},{"key":"2022061123201034254_j_popets-2021-0002_ref_007_w2aab3b7b4b1b6b1ab1ab7Aa","unstructured":"[7] S. D. Constable and S. Chapin. libOblivious: A c++ library for oblivious data structures and algorithms. In Electrical Engineering and Computer Science - Technical Reports. 184, 2018."},{"key":"2022061123201034254_j_popets-2021-0002_ref_008_w2aab3b7b4b1b6b1ab1ab8Aa","unstructured":"[8] V. Costan and S. Devadas. Intel sgx explained. IACR Cryptology ePrint Archive, 2016:86, 2016."},{"key":"2022061123201034254_j_popets-2021-0002_ref_009_w2aab3b7b4b1b6b1ab1ab9Aa","unstructured":"[9] J. Dean and S. Ghemawat. Mapreduce: Simplified data processing on large clusters. In OSDI, pages 137\u2013150, 2004."},{"key":"2022061123201034254_j_popets-2021-0002_ref_010_w2aab3b7b4b1b6b1ab1ac10Aa","unstructured":"[10] T. T. A. Dinh, P. Saxena, E. Chang, B. C. Ooi, and C. Zhang. M2R: enabling stronger privacy in mapreduce computation. In USENIX Security Symposium, pages 447\u2013462. USENIX Association, 2015."},{"key":"2022061123201034254_j_popets-2021-0002_ref_011_w2aab3b7b4b1b6b1ab1ac11Aa","unstructured":"[11] H. Gamaarachchi and H. Ganegoda. Power analysis based side channel attack. CoRR, abs\/1801.00932, 2018."},{"key":"2022061123201034254_j_popets-2021-0002_ref_012_w2aab3b7b4b1b6b1ab1ac12Aa","doi-asserted-by":"crossref","unstructured":"[12] O. Goldreich and R. Ostrovsky. Software protection and simulation on oblivious ram. Journal of the ACM, 43:431\u2013473, 1996.10.1145\/233551.233553","DOI":"10.1145\/233551.233553"},{"key":"2022061123201034254_j_popets-2021-0002_ref_013_w2aab3b7b4b1b6b1ab1ac13Aa","doi-asserted-by":"crossref","unstructured":"[13] Y. Huang, D. Evans, J. Katz, and L. Malka. Faster secure two-party computation using garbled circuits. In USENIX Conference on Security, pages 35\u201335, 2011.10.1007\/978-3-642-25560-1_2","DOI":"10.1007\/978-3-642-25560-1_2"},{"key":"2022061123201034254_j_popets-2021-0002_ref_014_w2aab3b7b4b1b6b1ab1ac14Aa","doi-asserted-by":"crossref","unstructured":"[14] A. Jain, M. Murty, and P. Flynn. Data clustering: A review. ACM Computing Surveys, 31:264\u2013323, 1999.","DOI":"10.1145\/331499.331504"},{"key":"2022061123201034254_j_popets-2021-0002_ref_015_w2aab3b7b4b1b6b1ab1ac15Aa","doi-asserted-by":"crossref","unstructured":"[15] T. Kim, J. Park, J. Woo, S. Jeon, and J. Huh. Shieldstore: Shielded in-memory key-value storage with sgx. In Proceedings of the Fourteenth EuroSys Conference 2019, EuroSys \u201919, New York, NY, USA, 2019. Association for Computing Machinery.10.1145\/3302424.3303951","DOI":"10.1145\/3302424.3303951"},{"key":"2022061123201034254_j_popets-2021-0002_ref_016_w2aab3b7b4b1b6b1ab1ac16Aa","doi-asserted-by":"crossref","unstructured":"[16] J. Lin and C. Dyer. Data-intensive text processing with MapReduce. Morgan and Claypool Publishers, 2010.10.2200\/S00274ED1V01Y201006HLT007","DOI":"10.1007\/978-3-031-02136-7"},{"key":"2022061123201034254_j_popets-2021-0002_ref_017_w2aab3b7b4b1b6b1ab1ac17Aa","unstructured":"[17] D. Lyubimov and A. Palumbo. Apache Mahout: Beyond MapReduce. CreateSpace Independent Publishing Platform, 2016."},{"key":"2022061123201034254_j_popets-2021-0002_ref_018_w2aab3b7b4b1b6b1ab1ac18Aa","unstructured":"[18] D. Miner and A. Shook. MapReduce Design Patterns: Building Effective Algorithms and Analytics for Hadoop and Other Systems. O\u2019Reilly Media, 2012."},{"key":"2022061123201034254_j_popets-2021-0002_ref_019_w2aab3b7b4b1b6b1ab1ac19Aa","doi-asserted-by":"crossref","unstructured":"[19] P. Mishra, R. Poddar, J. Chen, A. Chiesa, and R. A. Popa. Oblix: An efficient oblivious search index. In 2018 IEEE Symposium on Security and Privacy (SP), pages 279\u2013296, 2018.10.1109\/SP.2018.00045","DOI":"10.1109\/SP.2018.00045"},{"key":"2022061123201034254_j_popets-2021-0002_ref_020_w2aab3b7b4b1b6b1ab1ac20Aa","doi-asserted-by":"crossref","unstructured":"[20] P. Mohassel and Y. Zhang. Secureml: A system for scalable privacy-preserving machine learning. In 2017 IEEE Symposium on Security and Privacy (SP), pages 19\u201338, 2017.10.1109\/SP.2017.12","DOI":"10.1109\/SP.2017.12"},{"key":"2022061123201034254_j_popets-2021-0002_ref_021_w2aab3b7b4b1b6b1ab1ac21Aa","doi-asserted-by":"crossref","unstructured":"[21] V. Nikolaenko, U. Weinsberg, S. Ioannidis, M. Joye, D. Boneh, and N. Taft. Privacy-preserving ridge regression on hundreds of millions of records. In IEEE Symposium on Security and Privacy, pages 334\u2013348, 2013.10.1109\/SP.2013.30","DOI":"10.1109\/SP.2013.30"},{"key":"2022061123201034254_j_popets-2021-0002_ref_022_w2aab3b7b4b1b6b1ab1ac22Aa","unstructured":"[22] O. Ohrimenko, F. Schuster, C. Fournet, A. Mehta, S. Nowozin, K. Vaswani, and M. Costa. Oblivious multi-party machine learning on trusted processors. In 25th USENIX Security Symposium (USENIX Security 16), pages 619\u2013636, Austin, TX, 2016. USENIX Association."},{"key":"2022061123201034254_j_popets-2021-0002_ref_023_w2aab3b7b4b1b6b1ab1ac23Aa","unstructured":"[23] O. Ohrimenko, F. Schuster, C. Fournet, A. Mehta, S. Nowozin, K. Vaswani, and M. Costa. Oblivious multi-party machine learning on trusted processors. In 25th USENIX Security Symposium, USENIX Security 16, Austin, TX, USA, August 10-12, 2016., pages 619\u2013636, 2016."},{"key":"2022061123201034254_j_popets-2021-0002_ref_024_w2aab3b7b4b1b6b1ab1ac24Aa","unstructured":"[24] A. Rane, C. Lin, and M. Tiwari. Raccoon: Closing digital side-channels through obfuscated execution. In Proceedings of the 24th USENIX Conference on Security Symposium, SEC\u201915, page 431\u2013446, USA, 2015. USENIX Association."},{"key":"2022061123201034254_j_popets-2021-0002_ref_025_w2aab3b7b4b1b6b1ab1ac25Aa","doi-asserted-by":"crossref","unstructured":"[25] T. Ristenpart, E. Tromer, H. Shacham, and S. Savage. Hey, you, get off of my cloud: exploring information leakage in third-party compute clouds. In Proceedings of the 16th ACM conference on Computer and communications security, pages 199\u2013212, New York, NY, USA, 2009.10.1145\/1653662.1653687","DOI":"10.1145\/1653662.1653687"},{"key":"2022061123201034254_j_popets-2021-0002_ref_026_w2aab3b7b4b1b6b1ab1ac26Aa","unstructured":"[26] I. Roy, S. T. V. Setty, A. Kilzer, V. Shmatikov, and E. Witchel. Airavat: Security and privacy for mapreduce. In Proceedings of the 7th USENIX Conference on Networked Systems Design and Implementation, NSDI\u201910, pages 20\u201320, Berkeley, CA, USA, 2010. USENIX Association."},{"key":"2022061123201034254_j_popets-2021-0002_ref_027_w2aab3b7b4b1b6b1ab1ac27Aa","doi-asserted-by":"crossref","unstructured":"[27] S. Sasy, S. Gorbunov, and C. W. Fletcher. Zerotrace : Oblivious memory primitives from intel SGX. In 25th Annual Network and Distributed System Security Symposium, NDSS 2018, San Diego, California, USA, February 18-21, 2018, 2018.10.14722\/ndss.2018.23239","DOI":"10.14722\/ndss.2018.23239"},{"key":"2022061123201034254_j_popets-2021-0002_ref_028_w2aab3b7b4b1b6b1ab1ac28Aa","doi-asserted-by":"crossref","unstructured":"[28] F. Schuster, M. Costa, C. Fournet, C. Gkantsidis, M. Peinado, G. Mainar-Ruiz, and M. Russinovich. Vc3: Trustworthy data analytics in the cloud using sgx. In 36th IEEE Symposium on Security and Privacy, 2015.10.1109\/SP.2015.10","DOI":"10.1109\/SP.2015.10"},{"key":"2022061123201034254_j_popets-2021-0002_ref_029_w2aab3b7b4b1b6b1ab1ac29Aa","doi-asserted-by":"crossref","unstructured":"[29] S. Sharma and K. Chen. Confidential boosting with random linear classifiers for outsourced user-generated data. In Computer Security - ESORICS 2019 - 24th European Symposium on Research in Computer Security, Luxembourg, September 23-27, 2019, Proceedings, Part I, pages 41\u201365, 2019.10.1007\/978-3-030-29959-0_3","DOI":"10.1007\/978-3-030-29959-0_3"},{"key":"2022061123201034254_j_popets-2021-0002_ref_030_w2aab3b7b4b1b6b1ab1ac30Aa","doi-asserted-by":"crossref","unstructured":"[30] M.-W. Shih, S. Lee, T. Kim, and M. Peinado. T-sgx: Eradicating controlled-channel attacks against enclave programs. In Network and Distributed System Security Symposium 2017 (NDSS\u201917). Internet Society, February 2017.10.14722\/ndss.2017.23193","DOI":"10.14722\/ndss.2017.23193"},{"key":"2022061123201034254_j_popets-2021-0002_ref_031_w2aab3b7b4b1b6b1ab1ac31Aa","doi-asserted-by":"crossref","unstructured":"[31] S. Shinde, Z. L. Chua, V. Narayanan, and P. Saxena. Preventing page faults from telling your secrets. In Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security, ASIACCS16, page 317\u2013328, New York, NY, USA, 2016. Association for Computing Machinery.10.1145\/2897845.2897885","DOI":"10.1145\/2897845.2897885"},{"key":"2022061123201034254_j_popets-2021-0002_ref_032_w2aab3b7b4b1b6b1ab1ac32Aa","doi-asserted-by":"crossref","unstructured":"[32] E. Stefanov, M. V. Dijk, E. Shi, T.-H. H. Chan, C. Fletcher, L. Ren, X. Yu, and S. Devadas. Path oram: An extremely simple oblivious ram protocol. Journal of the ACM, 65(4), Apr. 2018.10.1145\/3177872","DOI":"10.1145\/3177872"},{"key":"2022061123201034254_j_popets-2021-0002_ref_033_w2aab3b7b4b1b6b1ab1ac33Aa","doi-asserted-by":"crossref","unstructured":"[33] X. Wang, H. Chan, and E. Shi. Circuit oram: On tightness of the goldreich-ostrovsky lower bound. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, CCS \u201915, page 850\u2013861, New York, NY, USA, 2015. Association for Computing Machinery.10.1145\/2810103.2813634","DOI":"10.1145\/2810103.2813634"},{"key":"2022061123201034254_j_popets-2021-0002_ref_034_w2aab3b7b4b1b6b1ab1ac34Aa","unstructured":"[34] M. Zaharia, M. Chowdhury, M. J. Franklin, S. Shenker, and I. Stoica. Spark: Cluster computing with working sets. In Proceedings of the 2Nd USENIX Conference on Hot Topics in Cloud Computing, HotCloud\u201910, pages 10\u201310, Berkeley, CA, USA, 2010. USENIX Association."},{"key":"2022061123201034254_j_popets-2021-0002_ref_035_w2aab3b7b4b1b6b1ab1ac35Aa","doi-asserted-by":"crossref","unstructured":"[35] X. Zhang, G. Li, and J. Feng. Crowdsourced top-k algorithms: An experimental evaluation. Proc. VLDB Endow., 9(8), Apr. 2016.10.14778\/2921558.2921559","DOI":"10.14778\/2921558.2921559"},{"key":"2022061123201034254_j_popets-2021-0002_ref_036_w2aab3b7b4b1b6b1ab1ac36Aa","unstructured":"[36] W. Zheng, A. Dave, J. G. Beekman, R. A. Popa, J. E. Gonzalez, and I. Stoica. Opaque: An oblivious and encrypted distributed analytics platform. In USENIX Symposium on Networked Systems Design and Implementation, 2017."}],"container-title":["Proceedings on Privacy Enhancing Technologies"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/content.sciendo.com\/view\/journals\/popets\/2021\/1\/article-p5.xml","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.sciendo.com\/pdf\/10.2478\/popets-2021-0002","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,10,15]],"date-time":"2023-10-15T22:56:24Z","timestamp":1697410584000},"score":1,"resource":{"primary":{"URL":"https:\/\/petsymposium.org\/popets\/2021\/popets-2021-0002.php"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,11,9]]},"references-count":36,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2020,11,9]]},"published-print":{"date-parts":[[2021,1,1]]}},"alternative-id":["10.2478\/popets-2021-0002"],"URL":"https:\/\/doi.org\/10.2478\/popets-2021-0002","relation":{},"ISSN":["2299-0984"],"issn-type":[{"value":"2299-0984","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,11,9]]}}}