Skip to main content
QUICK REVIEW

[논문 리뷰] The Pyramid Scheme: Oblivious RAM for Trusted Processors

Manuel Costa, Lawrence Esswood|arXiv (Cornell University)|2017. 12. 21.
Security and Verification in Computing참고 문헌 23인용 수 8
한 줄 요약

이 논문은 Intel SGX 신뢰형 프로세서를 위한 최적화된 계층적 무관람 RAM 기법인 Pyramid ORAM을 소개한다. 새로운 Zigzag 해시 테이블과 확률적 라우팅을 사용하여 상수 오버헤드와 온라인 대역폭을 최소화하였으며, 99%의 액세스에서 Circuit ORAM 대비 8배 낮은 지연 시간을 달성하면서도 프라이빗 메모리로 CPU 레지스터만을 사용한다.

ABSTRACT

Modern processors, e.g., Intel SGX, allow applications to isolate secret code and data in encrypted memory regions called enclaves. While encryption effectively hides the contents of memory, the sequence of address references issued by the secret code leaks information. This is a serious problem because these leaks can easily break the confidentiality guarantees of enclaves. In this paper, we explore Oblivious RAM (ORAM) designs that prevent these information leaks under the constraints of modern SGX processors. Most ORAMs are a poor fit for these processors because they have high constant overhead factors or require large private memories, which are not available in these processors. We address these limitations with a new hierarchical ORAM construction, the Pyramid ORAM, that is optimized towards online bandwidth cost and small blocks. It uses a new hashing scheme that circumvents the complexity of previous hierarchical schemes. We present an efficient x64-optimized implementation of Pyramid ORAM that uses only the processor's registers as private memory. We compare Pyramid ORAM with Circuit ORAM, a state-of-the-art tree-based ORAM scheme that also uses constant private memory. Pyramid ORAM has better online asymptotical complexity than Circuit ORAM. Our implementation of Pyramid ORAM and Circuit ORAM validates this: as all hierarchical schemes, Pyramid ORAM has high variance of access latencies; although latency can be high for some accesses, for typical configurations Pyramid ORAM provides access latencies that are 8X better than Circuit ORAM for 99% of accesses. Although the best known hierarchical ORAM has better asymptotical complexity, Pyramid ORAM has significantly lower constant overhead factors, making it the preferred choice in practice.

연구 동기 및 목표

  • 암호화에도 불구하고 기밀성에 위협이 되는 Intel SGX 에인클레이브 내의 메모리 액세스 패턴 泄露 문제를 해결한다.
  • 제한된 프라이빗 메모리와 높은 상수 오버헤드 제약 조건을 가진 현대 신뢰형 프로세서에 적합한 ORAM 체계를 설계한다.
  • x64 프로세서에서의 실용적 구현을 고려해 낮은 온라인 대역폭과 낮은 상수 요소를 최적화한다.
  • 큰 片上 스태시 요구 사항을 피하기 위해 프라이빗 메모리로 CPU 레지스터만을 사용하여 효율적이고 무관람 메모리 액세스를 가능하게 한다.
  • 예측 가능한 리빌드 스케줄링을 활용하여 계층적 ORAM이 최악의 경우 지연 시간이 더 높음에도 불구하고 실질적으로 트리 기반 기법보다 뛰어난 성능을 낼 수 있음을 입증한다.

제안 방법

  • 계층적 ORAM 구조를 제안하며, 핵심 데이터 구조로 새로운 Zigzag 해시 테이블(ZHT)을 사용한다.
  • 숨은 상수 없이 O(n log n) 시간 내에 ZHT를 무관람 방식으로 구성할 수 있는 확률적 라우팅 네트워크를 설계한다.
  • 임계값 기반 재삽입 전략을 사용한 다수준 적응형 해싱을 통해 오버플로 요소를 효율적으로 관리한다.
  • 큰 片上 스토리지에 의존하지 않고 CPU 레지스터만을 프라이빗 메모리로 사용하여 체계를 구현한다.
  • x64 Skylake 프로세서를 대상으로 저수준 명령어 수준 최적화를 통해 구현을 최적화한다.
  • 온라인 및 분할 비용 측면에서 Circuit ORAM(최첨단 트리 기반 ORAM)과 Pyramid ORAM을 비교한다.

실험 결과

연구 질문

  • RQ1계층적 ORAM 설계가 트리 기반 ORAM보다 더 낮은 온라인 점근적 복잡도를 달성하면서도 신뢰형 프로세서에서 낮은 상수 오버헤드를 유지할 수 있는가?
  • RQ2현대 x64 프로세서에서 최소한의 프라이빗 메모리와 낮은 상수 요소로 효과적으로 무관람 데이터 구조를 구성할 수 있는가?
  • RQ3계층적 ORAM의 예측 가능한 리빌드 단계는 균일 비용 트리 기반 기법 대비 지연 시간 변동성을 얼마나 줄이고 실질적 성능을 향상시킬 수 있는가?
  • RQ4Zigzag 해시 테이블과 같은 신규 해싱 체계가 계층적 ORAM에서 비용이 많이 드는 무관람 정렬이 필요 없어지는가?
  • RQ5Intel SGX에서 실제 워크로드에서 Pyramid ORAM과 Circuit ORAM 간의 실질적 성능 트레이드오프는 어떠한가?

주요 결과

  • Pyramid ORAM은 Circuit ORAM보다 더 낮은 대역폭 비용으로 더 낮은 온라인 점근적 복잡도를 달성한다.
  • 일반적인 설정에서 Pyramid ORAM은 99%의 액세스에서 Circuit ORAM 대비 최소 8배 낮은 액세스 지연 시간을 기록한다.
  • 구현은 프라이빗 메모리로 CPU 레지스터만을 사용하여 큰 片上 스태시나 외부 메모리가 필요 없도록 한다.
  • 최악의 경우 지연 시간이 더 높음에도 불구하고 Pyramid ORAM의 예측 가능한 리빌드 스케줄링 덕분에 고지연 액세스의 빈도가 감소하여 사전 최적화가 가능하다.
  • 매우 낮은 상수 오버헤드 요소 덕분에 Pyramid ORAM은 실질적으로 기존 최고 수준의 계층적 ORAM을 능가한다.
  • 이 작업은 Intel SGX에서 계층적 ORAM의 첫 번째 실험적 평가를 제공하며, 실제 벤치마크에서 트리 기반 대안보다 실질적으로 열등하지 않음을 입증한다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.