PRIMaTE
PRIMaTE: PRIvacy preserving Multi-compartment Trusted Execution
(Third Party Funds Single)
Project leader:
Start date: 16. October 2017
End date: 16. October 2020
Extension Date: 31. August 2023
Acronym: PRIMaTE
Funding source: Deutsche Forschungsgemeinschaft (DFG)
Abstract:
Nowadays, a wide variety of online services (e.g., web search engines, location-based services, recommender systems) are being used by billions of users on a daily basis. Key to the success of these services is the personalisation of their results, that is returning to each user those results that are closer to their interests. For instance, given a web search query sent by two different users, search engines generally rank differently the search results to best fit each user's preferences. However, according to the underlying application, user profiles may contain sensitive information about end users. In this context, it becomes urgent to devise mechanisms that allow users to securely access online services without fearing that their data will be leaked out from the cloud platforms where it is being stored and processed.
The proposed PRIMaTE project addresses privacy-preserving in online services. We propose a system that reduces and precisely specifies trust assumptions, while still providing improved performance compared to the state of the art. Our key contribution will be to systematically decompose these services in strongly hardware-secured compartments, where each has access only to the data essential for performing the assigned task. In case of security breaches for example due to attackers exploiting a weakness in the code of one or even multiple compartments, the impact of the leaked data will be kept at bounds and their effect can be precisely quantified. Thus, the attacker might only learn certain aspects of a profile but cannot link it to a user. PRIMaTE achieves this goal by utilizing novel trusted execution support offered by recent commodity processors such as the 2016 introduced Skylake generation of Intel processors. Trusted execution as offered by Intel Software Guard Extensions (SGX) is a disruptive technology that will impact how code and data is protected in the future.
PRIMaTE will utilize trusted execution to devise novel privacy-preserving online services. While current research on trusted execution focused either on deploying whole legacy applications such as a databases in a single Trusted Execution Environment (TEE) or on ad-hoc solutions to split existing applications into two parts - a trusted and untrusted one - PRIMaTE aims for a more systematic and fine-grained approach. It targets to develop a methodology to split privacy-preserving online services into multiple interacting compartments each implemented by a TEE. Thereby, each TEE should handle as little data as possible and have a tailored and therefore minimal trusted computing base. While the latter makes it hard to exploit a PRIMaTE TEE, the former limits the exposed information if an attacker is able to successfully break into a TEE.
Publications:
CYCLOSA: Decentralizing private web search through SGX-Based browser extensions
38th IEEE International Conference on Distributed Computing Systems, ICDCS 2018 (Vienna, AUT, 2. July 2018 - 5. July 2018)
In: Proceedings - International Conference on Distributed Computing Systems 2018
DOI: 10.1109/ICDCS.2018.00053 , , , , , , , , :
Eactors: Fast and flexible trusted computing using SGX
19th ACM/IFIP/USENIX International Middleware Conference, Middleware 2018 (Rennes, Brittany, FRA, 10. December 2018 - 14. December 2018)
In: Proceedings of the 19th International Middleware Conference, Middleware 2018 2018
DOI: 10.1145/3274808.3274823 , , , , , :
Trusted execution, and the impact of security on performance
3rd Workshop on System Software for Trusted Execution, SysTEX 2018, co-located with CCS 2018 (Toronto, ON, CAN, 15. October 2018)
In: Proceedings of the ACM Conference on Computer and Communications Security 2018
DOI: 10.1145/3268935.3268943 , , :
Acctee: A WebAssembly-based Two-way Sandbox for Trusted Resource Accounting
20th ACM/IFIP/USENIX Middleware Conference, Middleware 2019 (Davis, CA, USA, 9. December 2019 - 13. December 2019)
In: Middleware 2019 - Proceedings of the 2019 20th International Middleware Conference 2019
DOI: 10.1145/3361525.3361541 , , , :
Edgedancer: Secure Mobile WebAssembly Services on the Edge
4th International Workshop on Edge Systems, Analytics and Networking, EdgeSys 2021, in conjunction with ACM EuroSys 2021 (Virtual, Online, GBR, 26. April 2021)
In: EdgeSys 2021 - Proceedings of the 4th International Workshop on Edge Systems, Analytics and Networking, Part of EuroSys 2021 2021
DOI: 10.1145/3434770.3459731 , , :