We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: SHORTSTACK: Distributed, Fault-tolerant, Oblivious Data Access

Authors: Midhul Vuppalapati (1), Kushal Babel (1), Anurag Khandelwal (2), Rachit Agarwal (1) ((1) Cornell University, (2) Yale University)
Abstract: Many applications that benefit from data offload to cloud services operate on private data. A now-long line of work has shown that, even when data is offloaded in an encrypted form, an adversary can learn sensitive information by analyzing data access patterns. Existing techniques for oblivious data access-that protect against access pattern attacks-require a centralized and stateful trusted proxy to orchestrate data accesses from applications to cloud services. We show that, in failure-prone deployments, such a centralized and stateful proxy results in violation of oblivious data access security guarantees and/or system unavailability. We thus initiate the study of distributed, fault-tolerant, oblivious data access.
We present SHORTSTACK, a distributed proxy architecture for oblivious data access in failure-prone deployments. SHORTSTACK achieves the classical obliviousness guarantee--access patterns observed by the adversary being independent of the input--even under a powerful passive persistent adversary that can force failure of arbitrary (bounded-sized) subset of proxy servers at arbitrary times. We also introduce a security model that enables studying oblivious data access with distributed, failure-prone, servers. We provide a formal proof that SHORTSTACK enables oblivious data access under this model, and show empirically that SHORTSTACK performance scales near-linearly with number of distributed proxy servers.
Comments: Full version of USENIX OSDI'22 paper
Subjects: Cryptography and Security (cs.CR); Distributed, Parallel, and Cluster Computing (cs.DC); Networking and Internet Architecture (cs.NI)
Journal reference: In 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI 22), pp. 719-734. 2022
Cite as: arXiv:2205.14281 [cs.CR]
  (or arXiv:2205.14281v2 [cs.CR] for this version)

Submission history

From: Kushal Babel [view email]
[v1] Sat, 28 May 2022 00:33:35 GMT (3238kb,D)
[v2] Wed, 8 Jun 2022 06:23:32 GMT (2883kb,D)

Link back to: arXiv, form interface, contact.