Secure Delegator Offloads Path ORAM for Untrusted Cloud Memory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing security is compromised due to untrusted memory in cloud servers, where memory access patterns leak sensitive information, and existing solutions like Path ORAM introduce memory contention and performance degradation.

Innovation Solution

A dynamic oblivious memory apparatus (D-ORAM) with a trusted computing base consisting of a processor and a secure delegator, using one-time-pad encryption and Path ORAM delegation via a buffer-on-board architecture, integrates securely with commercially available untrusted memory modules, offloading expensive Path ORAM primitives from the processor.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Path ORAM is implemented to protect data privacy on untrusted memory, then security protection is improved, but memory contention and performance degradation occur

Engineering Contradiction:
Improvedata privacy protectionVSAvoidmemory access performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments the memory controller functionality by introducing a separate secure delegator component that handles Path ORAM operations independently from the main processor. This segmentation allows the processor to offload expensive ORAM primitives while maintaining security, thereby reducing memory contention and improving overall system performance without compromising data privacy protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure delegator is introduced as an intermediary component between the processor and untrusted memory modules. This delegator performs Path ORAM operations and acts as a mediator that protects communication between the processor and memory modules arranged outside the TCB, enabling security protection without requiring the processor to directly handle expensive ORAM primitives.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If Path ORAM converts one memory access to hundreds of memory accesses to protect against access pattern leakage, then security protection is improved, but memory contention increases

Engineering Contradiction:
Improveaccess pattern protectionVSAvoidmemory contention
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the memory access operations by having the secure delegator handle the expansion of single memory accesses into multiple ORAM accesses independently. This segmentation prevents the main processor from being directly involved in the contention-prone ORAM operations, thereby maintaining access pattern protection while reducing the harmful effects of memory contention on overall system performance.

Inventive Principle:
Principle #1Segmentation

3Reliability

If a secure memory model places both processor and main memory module in the TCB to protect data privacy, then security protection is improved, but compatibility with mainstream server hardware is reduced

Engineering Contradiction:
Improvedata privacy protectionVSAvoidhardware compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The secure delegator serves as an intermediary that enables the secure memory model to work with mainstream server hardware. By placing the secure delegator in the TCB while allowing memory modules to remain outside the TCB, the system achieves data privacy protection through communication channel encryption and Path ORAM without requiring modification of existing untrusted DRAM modules, thereby maintaining hardware compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If communication between processor and untrusted memory modules is encrypted to protect data privacy, then security protection is improved, but processor resource utilization is reduced

Engineering Contradiction:
Improvecommunication securityVSAvoidprocessor resource utilization
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system extracts the cryptographic operations and Path ORAM primitives from the processor and relocates them to a separate secure delegator component. This extraction allows the processor to focus on computation while the secure delegator handles security-sensitive operations, thereby improving processor resource utilization without compromising communication security between the processor and untrusted memory modules.

Inventive Principle:
Principle #2Taking out (Extraction)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

D-ORAM provides high-level security protection, low interference between secure and non-secure applications, and good compatibility with mainstream server hardware, mitigating memory contention and enhancing processor resource utilization.

Implementation Method 1

The secure delegator protects the communication between the processor and itself by using encryption

Methodology Applied
Scientific EffectOne-time-pad encryption:

Implementation Method 2

the secure delegator performs Path ORAM accesses to untrusted memory modules

Methodology Applied
Scientific EffectPath ORAM protocol:

Data Source

PatentUS11243881B2Practical ORAM delegation for untrusted memory on cloud servers
Publication Date: 2022.02.08 UNIV OF PITTSBURGH OF THE COMMONWEALTH SYST OF HIGHER EDUCATION
  • US11243881B2 patent drawing
  • US11243881B2 patent drawing
  • US11243881B2 patent drawing

AI summary

An apparatus including (i) a processor including a plurality of main buffer on board (BOB) memory controllers (MCs) and a secure engine, (ii) a plurality of simple BOB MCs, (iii) a secure delegator, and (iv) a plurality of memory modules. The secure delegator coupled to a first main BOB MC and a first simple BOB MC creates a secure channel. A second main BOB MC coupled to a second simple BOB MC creates a non-secure channel. The plurality of main BOB MCs, the secure engine and the secure delegator are provided within a trusted computing base (TCB) of the apparatus and the plurality of simple BOB MCs and the plurality of memory modules are provided outside the TCB. The secure delegator is configured to: (i) secure communication between the first main BOB MC and the secure delegator, and (ii) perform Path ORAM accesses to the plurality of memory modules.