Sharing without Showing: Secure Cloud Analytics with Trusted Execution Environments

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Birgersson, Marcus, Artho, Cyrille, Balliu, Musard
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929541130223616
author Birgersson, Marcus
Artho, Cyrille
Balliu, Musard
author_facet Birgersson, Marcus
Artho, Cyrille
Balliu, Musard
contents Many applications benefit from computations over the data of multiple users while preserving confidentiality. We present a solution where multiple mutually distrusting users' data can be aggregated with an acceptable overhead, while allowing users to be added to the system at any time without re-encrypting data. Our solution to this problem is to use a Trusted Execution Environment (Intel SGX) for the computation, while the confidential data is encrypted with the data owner's key and can be stored anywhere, without trust in the service provider. We do not require the user to be online during the computation phase and do not require a trusted party to store data in plain text. Still, the computation can only be carried out if the data owner explicitly has given permission. Experiments using common functions such as the sum, least square fit, histogram, and SVM classification, exhibit an average overhead of $1.6 \times$. In addition to these performance experiments, we present a use case for computing the distributions of taxis in a city without revealing the position of any other taxi to the other parties.
format Preprint
id arxiv_https___arxiv_org_abs_2410_10574
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Sharing without Showing: Secure Cloud Analytics with Trusted Execution Environments
Birgersson, Marcus
Artho, Cyrille
Balliu, Musard
Cryptography and Security
Many applications benefit from computations over the data of multiple users while preserving confidentiality. We present a solution where multiple mutually distrusting users' data can be aggregated with an acceptable overhead, while allowing users to be added to the system at any time without re-encrypting data. Our solution to this problem is to use a Trusted Execution Environment (Intel SGX) for the computation, while the confidential data is encrypted with the data owner's key and can be stored anywhere, without trust in the service provider. We do not require the user to be online during the computation phase and do not require a trusted party to store data in plain text. Still, the computation can only be carried out if the data owner explicitly has given permission. Experiments using common functions such as the sum, least square fit, histogram, and SVM classification, exhibit an average overhead of $1.6 \times$. In addition to these performance experiments, we present a use case for computing the distributions of taxis in a city without revealing the position of any other taxi to the other parties.
title Sharing without Showing: Secure Cloud Analytics with Trusted Execution Environments
topic Cryptography and Security
url https://arxiv.org/abs/2410.10574