Skip to main content
QUICK REVIEW

[논문 리뷰] Revisiting Definitional Foundations of Oblivious RAM for Secure Processor Implementations

Syed Kamran Haider, Omer Khan|arXiv (Cornell University)|2017. 06. 12.
Security and Verification in Computing참고 문헌 29인용 수 5
한 줄 요약

이 논문은 현대의 보안 프로세서 구현에서 발생하는 변수 길이의 액세스 시퀀스와 프로그램 종료, 캐싱으로 인한 정보 유출이라는 실용적 격차를 해결하기 위해 옴니버러스 랜덤 액세스 메모리(ORAM) 보안 정의를 재정의한다. 새로운 ORAM 체계를 제안하여 종료 채널 유출을 분리하고, 스태시 크기 및 오버플로우 제약 조건을 완화함으로써 Path ORAM의 보안 분석을 단순화하며, 최소한의 성능 손실로 내부 사이드 채널을 완화하기 위한 동적 자원 분할 프레임워크를 도입한다.

ABSTRACT

Oblivious RAM (ORAM) is a renowned technique to hide the access patterns of an application to an untrusted memory. According to the standard ORAM definition presented by Goldreich and Ostrovsky, two ORAM access sequences must be computationally indistinguishable if the lengths of these sequences are identically distributed. An artifact of this definition is that it does not apply to modern ORAM implementations adapted in current secure processors technology because of their arbitrary lengths of memory access sequences depending on programs' behaviors (their termination times). As a result, the ORAM definition does not directly apply; the theoretical foundations of ORAM do not clearly argue about the timing and termination channels. This paper conducts a first rigorous study of the standard Goldreich-Ostrovsky ORAM definition in view of modern practical ORAMs (e.g., Path ORAM) and demonstrates the gap between theoretical foundations and real implementations. A new ORAM formulation which clearly separates out termination channel leakage is proposed. It is shown how this definition implies the standard ORAM definition (for finite length input access sequences) and better fits the modern practical ORAM implementations. The proposed definition relaxes the constraints around the stash size and overflow probability for Path ORAM, and essentially transforms its security argument into a performance consideration problem. Finally, a `strong' ORAM formulation which clearly includes obfuscation of termination leakage is shown to imply our new ORAM formulation and applies to ORAM for outsourced disk storage. In this strong formulation constraints are not relaxed and the security argument for Path ORAM remains complex as one needs to prove that the stash overflows with negligible probability.

연구 동기 및 목표

  • 이론적 ORAM 정의와 현대의 보안 프로세서 구현 간의 괴리, 특히 변수 길이 ORAM 액세스 시퀀스를 사용하는 환경에서의 유출 문제를 규명하기 위해.
  • 종료 채널 유출을 메모리 액세스 패턴 유출에서 명시적으로 분리하는 새로운 ORAM 보안 정의를 체계화하기 위해.
  • 스태시 크기 및 오버플로우 확률 제약 조건을 완화함으로써 Path ORAM의 보안 분석을 단순화하기 위해.
  • DRAM 대역폭 및 ORAM 액세스 레이트와 같은 공유 하드웨어 자원에서 발생하는 내부 사이드 채널을 완화하기 위해.
  • 다중 스레드 보안 프로세서 환경에서 성능과 유출을 균형 잡는 일반적인 동적 자원 분할 프레임워크를 제공하기 위해.

제안 방법

  • 종료 채널 유출을 액세스 패턴 유출과 별개의 유출 원천으로 명시적으로 모델링하는 새로운 ORAM 체계를 제안한다.
  • 제안된 체계가 유한 길이 입력 시퀀스에 대해 원래의 Goldreich-Ostrovsky ORAM 정의를 함의함을 입증한다.
  • 성능 및 개인정보 보호 지표에 기반해 에포크 단위로 자원 할당을 조정하는 동적 자원 분할 프레임워크를 도입한다.
  • 과거 기록과 성능 지표를 바탕으로 구성 변경을 결정하는 함수 $\mathcal{F}$ 를 사용하여, 오직 스레드별 정보만이 누출되도록 보장한다.
  • 샤논 엔트로피를 이용한 정보 이론적 한계를 적용하여 개인정보 유출을 $H(PastHist_i)$ 로 정량화하며, 이는 $\sum_j \lambda_j = \sum_j \log|C^{(j-1)}|$ 로 제한된다.
  • 이중 단계 메커니즘을 적용: 에포크별 정적 할당으로 내부 사이드 채널을 방지하고, 실제/가짜 ORAM 액세스를 구분할 수 없도록 하여 외부 유출을 방지한다.

실험 결과

연구 질문

  • RQ1표준 Goldreich-Ostrovsky ORAM 정의는 변수 길이 ORAM 시퀀스를 사용하는 현대 보안 프로세서 환경에서 어떤 방식으로 유출을 포괄하지 못하는가?
  • RQ2종료 채널 유출을 분리하면서도 보안 보장을 유지할 수 있는 새로운 ORAM 체계를 설계할 수 있는가?
  • RQ3스태시 크기 및 오버플로우 제약 조건을 완화함으로써 Path ORAM의 보안 분석을 얼마나 단순화할 수 있는가?
  • RQ4DRAM 대역폭 및 ORAM 액세스 레이트와 같은 공유 하드웨어 자원에서 발생하는 내부 사이드 채널을 성능 손실 없이 완화할 수 있는가?
  • RQ5다중 스레드 보안 프로세서 환경에서 제어 가능하고 유한한 유출을 보장하는 동적 자원 분할 프레임워크를 구성할 수 있는가?

주요 결과

  • 제안된 ORAM 체계는 종료 채널 유출을 명시적으로 분리하여, 이를 액세스 패턴 유출과 별도로 분석할 수 있도록 한다.
  • 새로운 체계는 유한 길이 입력 시퀀스에 대해 원래의 Goldreich-Ostrovsky 정의를 함의하므로 후행 호환성이 보장된다.
  • Path ORAM의 보안 논증은 복잡한 확률적 오버플로우 증명에서 성능 고려 사항으로 전환되어 분석이 크게 단순화된다.
  • 동적 자원 분할 프레임워크는 스레드별 구성 기록의 엔트로피에 기반해 최대 $\sum_j \lambda_j$ 비트의 개인정보 유출로 제한되며, 여기서 $\lambda_j = \log|C^{(j-1)}|$ 이다.
  • 최소한의 성능 손실로 DRAM 대역폭 및 ORAM 액세스 레이트와 같은 공유 자원 경쟁에서 발생하는 사이드 채널을 효과적으로 완화한다.
  • 종료 가림 기능을 포함하고 외부 디스크 스토리지에 적용 가능한 '강력한'(strong) ORAM 체계를 도입하여, 제약 조건을 완화하지 않고도 전체 보안을 유지한다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.