Paper Abstract and Keywords |
Presentation |
2022-09-02 13:20
Data protection mechanism for RDBMS using both trust and untrust regions in TEE Masashi Yoshimura, Yuzo Taenaka, Youki Kadobayashi (NAIST) NS2022-71 |
Abstract |
(in Japanese) |
(See Japanese page) |
(in English) |
With the spread of cloud computing, database services, which are basically under a heavy load are now on the cloud. As cloud, cloud service providers have higher permission than database and system administrators, even if the OS and database are robust, reading or leaking of confidential data by cloud service providers is a significant threat yet. A hardware-assisted security mechanism called TEE (Trusted Execution Environment), has been installed in CPUs to protect data and processes from cloud providers.TEE allows programs to run while protecting processes and memory in an isolated environment (trust area). However, as TEE allocates dedicated CPU/memory resources for a protected trusted region, it is not possible to use all of the server’s resources; resources allocated for running OS and other processes, called untrust region, is remaining. Especially in the case of protecting data and processes in a high-load database, situations frequently occur where only the Trust region is overloaded and the resources in the Untrust area remain, resulting in low resource utilization efficiency. Therefore, this study proposes a data protection mechanism for RDBMS that protects sensitive data while effectively utilizing the resources of both Trust and Untrust areas by executing only the elements that handle sensitive data in the Trust area. |
Keyword |
(in Japanese) |
(See Japanese page) |
(in English) |
Data Protection / RDBMS / Intel SGX / TEE / Cloud / / / |
Reference Info. |
IEICE Tech. Rep., vol. 122, no. 170, NS2022-71, pp. 60-65, Sept. 2022. |
Paper # |
NS2022-71 |
Date of Issue |
2022-08-25 (NS) |
ISSN |
Online edition: ISSN 2432-6380 |
Copyright and reproduction |
All rights are reserved and no part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopy, recording, or any information storage and retrieval system, without permission in writing from the publisher. Notwithstanding, instructors are permitted to photocopy isolated articles for noncommercial classroom use without fee. (License No.: 10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
Download PDF |
NS2022-71 |
Conference Information |
Committee |
NS IN CS NV |
Conference Date |
2022-09-01 - 2022-09-02 |
Place (in Japanese) |
(See Japanese page) |
Place (in English) |
MALIOS (Iwate Prefecture) + Online Meeting |
Topics (in Japanese) |
(See Japanese page) |
Topics (in English) |
Session management (SIP/IMS), Interoperability/Standardization, NGN/NwGN/Future networks, Cloud/Data center networks, SDN (OpenFlow, etc.)/NFV, IPv6, Machine learning, etc. |
Paper Information |
Registration To |
NS |
Conference Code |
2022-09-NS-IN-CS-NV |
Language |
Japanese |
Title (in Japanese) |
(See Japanese page) |
Sub Title (in Japanese) |
(See Japanese page) |
Title (in English) |
Data protection mechanism for RDBMS using both trust and untrust regions in TEE |
Sub Title (in English) |
|
Keyword(1) |
Data Protection |
Keyword(2) |
RDBMS |
Keyword(3) |
Intel SGX |
Keyword(4) |
TEE |
Keyword(5) |
Cloud |
Keyword(6) |
|
Keyword(7) |
|
Keyword(8) |
|
1st Author's Name |
Masashi Yoshimura |
1st Author's Affiliation |
Nara Institute of Science and Technology (NAIST) |
2nd Author's Name |
Yuzo Taenaka |
2nd Author's Affiliation |
Nara Institute of Science and Technology (NAIST) |
3rd Author's Name |
Youki Kadobayashi |
3rd Author's Affiliation |
Nara Institute of Science and Technology (NAIST) |
4th Author's Name |
|
4th Author's Affiliation |
() |
5th Author's Name |
|
5th Author's Affiliation |
() |
6th Author's Name |
|
6th Author's Affiliation |
() |
7th Author's Name |
|
7th Author's Affiliation |
() |
8th Author's Name |
|
8th Author's Affiliation |
() |
9th Author's Name |
|
9th Author's Affiliation |
() |
10th Author's Name |
|
10th Author's Affiliation |
() |
11th Author's Name |
|
11th Author's Affiliation |
() |
12th Author's Name |
|
12th Author's Affiliation |
() |
13th Author's Name |
|
13th Author's Affiliation |
() |
14th Author's Name |
|
14th Author's Affiliation |
() |
15th Author's Name |
|
15th Author's Affiliation |
() |
16th Author's Name |
|
16th Author's Affiliation |
() |
17th Author's Name |
|
17th Author's Affiliation |
() |
18th Author's Name |
|
18th Author's Affiliation |
() |
19th Author's Name |
|
19th Author's Affiliation |
() |
20th Author's Name |
|
20th Author's Affiliation |
() |
Speaker |
Author-1 |
Date Time |
2022-09-02 13:20:00 |
Presentation Time |
25 minutes |
Registration for |
NS |
Paper # |
NS2022-71 |
Volume (vol) |
vol.122 |
Number (no) |
no.170 |
Page |
pp.60-65 |
#Pages |
6 |
Date of Issue |
2022-08-25 (NS) |
|