TEE-based General-purpose Computational Backend for Secure Delegated Data Processing

Author:

Sha Mo1ORCID,Li Jialin2ORCID,Wang Sheng1ORCID,Li Feifei3ORCID,Tan Kian-Lee2ORCID

Affiliation:

1. Alibaba Group, Singapore, Singapore

2. National University of Singapore, Singapore, Singapore

3. Alibaba Group, Hangzhou, China

Abstract

The increasing prevalence of data breaches necessitates robust data protection measures in computational tasks. Secure computation outsourcing (SCO) presents a viable solution by safeguarding the confidentiality of inputs and outputs in data processing without disclosure. Nonetheless, this approach assumes the existence of a trustworthy coordinator to orchestrate and oversee the process, typically implying that data owners must fulfill this role themselves. In this paper, we consider secure delegated data processing (SDDP), an expanded data processing scenario wherein data owners simply delegate their data to SDDP providers for subsequent value mining or other downstream applications, eliminating the necessary involvement of data owners or trusted entities to dive into data processing deeply. However, general-purpose SDDP poses significant challenges in permitting the discretionary execution of computational tasks by SDDP providers on sensitive data while ensuring confidentiality. Existing approaches are insufficient to support SDDP in either efficiency or universality. To tackle this issue, we propose TGCB, a TEE-based General-purpose Computational Backend, designed to endow general-purpose computation with SDDP capabilities from an engineering perspective, powered by TEE-based code integrity and data confidentiality. Central to TGCB is the Encryption Programming Language (EPL) that defines computational tasks in SDDP. Specifically, SDDP providers can express arbitrary computable functions as EPL scripts, processed by TGCB's interfaces, securely interpreted and executed in TEE, ensuring data confidentiality throughout the process. As a universal computational backend, TGCB extensively bolsters data security in existing general-purpose computational tasks, allowing data owners to leverage SDDP without privacy concerns.

Publisher

Association for Computing Machinery (ACM)

Reference104 articles.

1. Panagiotis Antonopoulos , Arvind Arasu , Kunal D. Singh , Ken Eguro , Nitish Gupta , Rajat Jain , Raghav Kaushik , Hanuma Kodavalla , Donald Kossmann , Nikolas Ogg , Ravi Ramamurthy , Jakub Szymaszek , Jeffrey Trimmer , Kapil Vaswani , Ramarathnam Venkatesan , and Mike Zwilling . 2020 . Azure SQL Database Always Encrypted. In SIGMOD Conference. ACM, 1511--1525 . Panagiotis Antonopoulos, Arvind Arasu, Kunal D. Singh, Ken Eguro, Nitish Gupta, Rajat Jain, Raghav Kaushik, Hanuma Kodavalla, Donald Kossmann, Nikolas Ogg, Ravi Ramamurthy, Jakub Szymaszek, Jeffrey Trimmer, Kapil Vaswani, Ramarathnam Venkatesan, and Mike Zwilling. 2020. Azure SQL Database Always Encrypted. In SIGMOD Conference. ACM, 1511--1525.

2. Arvind Arasu , Ken Eguro , Manas Joglekar , Raghav Kaushik , Donald Kossmann , and Ravi Ramamurthy . 2015. Transaction processing on confidential data using cipherbase . In ICDE. IEEE Computer Society , 435--446. Arvind Arasu, Ken Eguro, Manas Joglekar, Raghav Kaushik, Donald Kossmann, and Ravi Ramamurthy. 2015. Transaction processing on confidential data using cipherbase. In ICDE. IEEE Computer Society, 435--446.

3. Spark SQL

4. Sergei Arnautov , Bohdan Trach , Franz Gregor , Thomas Knauth , André Martin , Christian Priebe , Joshua Lind , Divya Muthukumaran , Dan O'Keeffe , Mark Stillwell , David Goltzsche , David M. Eyers , Rü diger Kapitza , Peter R. Pietzuch, and Christof Fetzer. 2016 . SCONE : Secure Linux Containers with Intel SGX. In OSDI. USENIX Association , 689--703. Sergei Arnautov, Bohdan Trach, Franz Gregor, Thomas Knauth, André Martin, Christian Priebe, Joshua Lind, Divya Muthukumaran, Dan O'Keeffe, Mark Stillwell, David Goltzsche, David M. Eyers, Rü diger Kapitza, Peter R. Pietzuch, and Christof Fetzer. 2016. SCONE: Secure Linux Containers with Intel SGX. In OSDI. USENIX Association, 689--703.

5. Mikhail J. Atallah and Keith B . Frikken . 2010 . Securely outsourcing linear algebra computations. In AsiaCCS. ACM , 48--59. Mikhail J. Atallah and Keith B. Frikken. 2010. Securely outsourcing linear algebra computations. In AsiaCCS. ACM, 48--59.

Cited by 1 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3