Flare: A Fast, Secure, and Memory-Efficient Distributed Analytics Framework

Author:

Li Xiang1,Li Fabing2,Gao Mingyu3

Affiliation:

1. Tsinghua University

2. Xi'an Jiaotong University

3. Tsinghua University, Shanghai Artificial Intelligence Lab, Shanghai Qi Zhi Institute

Abstract

As big data processing in the cloud becomes prevalent today, data privacy on such public platforms raises critical concerns. Hardware-based trusted execution environments (TEEs) provide promising and practical platforms for low-cost privacy-preserving data processing. However, using TEEs to enhance the security of data analytics frameworks like Apache Spark involves challenging issues when separating various framework components into trusted and untrusted domains, demanding meticulous considerations for programmability, performance, and security. Based on Intel SGX, we build Flare, a fast, secure, and memory-efficient data analytics framework with a familiar user programming interface and useful functionalities similar to Apache Spark. Flare ensures confidentiality and integrity by keeping sensitive data and computations encrypted and authenticated. It also supports oblivious processing to protect against access pattern side channels. The main innovations of Flare include a novel abstraction paradigm of shadow operators and shadow tasks to minimize trusted components and reduce domain switch overheads, memory-efficient data processing with proper granularities for different operators, and adaptive parallelization based on memory allocation intensity for better scalability. Flare outperforms the state-of-the-art secure framework by 3.0× to 176.1×, and is also 2.8× to 28.3× faster than a monolithic libOS-based integration approach.

Publisher

Association for Computing Machinery (ACM)

Subject

General Earth and Planetary Sciences,Water Science and Technology,Geography, Planning and Development

Reference87 articles.

1. Tiago Alves . 2004. TrustZone: Integrated Hardware and Software Security. White paper ( 2004 ). Tiago Alves. 2004. TrustZone: Integrated Hardware and Software Security. White paper (2004).

2. Ittai Anati , Shay Gueron , Simon Johnson , and Vincent Scarlata . 2013 . Innovative Technology for CPU Based Attestation and Sealing . In Proceedings of the 2nd International Workshop on Hardware and Architectural Support for Security and Privacy. Ittai Anati, Shay Gueron, Simon Johnson, and Vincent Scarlata. 2013. Innovative Technology for CPU Based Attestation and Sealing. In Proceedings of the 2nd International Workshop on Hardware and Architectural Support for Security and Privacy.

3. Sergei Arnautov , Bohdan Trach , Franz Gregor , Thomas Knauth , Andre Martin , Christian Priebe , Joshua Lind , Divya Muthukumaran , Dan O'Keeffe , Mark L. Still-well, David Goltzsche , Dave Eyers , Rüdiger Kapitza , Peter Pietzuch , and Christof Fetzer . 2016 . SCONE: Secure Linux Containers with Intel SGX . In Proceedings of 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI). 689--703 . Sergei Arnautov, Bohdan Trach, Franz Gregor, Thomas Knauth, Andre Martin, Christian Priebe, Joshua Lind, Divya Muthukumaran, Dan O'Keeffe, Mark L. Still-well, David Goltzsche, Dave Eyers, Rüdiger Kapitza, Peter Pietzuch, and Christof Fetzer. 2016. SCONE: Secure Linux Containers with Intel SGX. In Proceedings of 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI). 689--703.

4. Maurice Bailleu , Dimitra Giantsidi , Vasilis Gavrielatos , Do Le Quoc , Vijay Nagarajan , and Pramod Bhatotia . 2021 . Avocado: A Secure In-Memory Distributed Storage System . In Proceedings of the 2021 USENIX Annual Technical Conference (USENIX ATC). 65--79 . Maurice Bailleu, Dimitra Giantsidi, Vasilis Gavrielatos, Do Le Quoc, Vijay Nagarajan, and Pramod Bhatotia. 2021. Avocado: A Secure In-Memory Distributed Storage System. In Proceedings of the 2021 USENIX Annual Technical Conference (USENIX ATC). 65--79.

5. TrustedDB: A Trusted Hardware-Based Database with Privacy and Data Confidentiality;Bajaj Sumeet;IEEE Transactions on Knowledge and Data Engineering (TKDE),2013

Cited by 3 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Demystifying the QoS and QoE of Edge-hosted Video Streaming Applications in the Wild with SNESet;Proceedings of the ACM on Management of Data;2023-12-08

2. Preemptive Switch Memory Usage to Accelerate Training Jobs with Shared In-Network Aggregation;2023 IEEE 31st International Conference on Network Protocols (ICNP);2023-10-10

3. SODA: A Set of Fast Oblivious Algorithms in Distributed Secure Data Analytics;Proceedings of the VLDB Endowment;2023-03

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3