Using Trusted Execution Environments for Secure Stream Processing of Medical Data (Case Study Paper)

被引:10
作者
Segarra, Carlos [1 ]
Delgado-Gonzalo, Ricard [1 ]
Lemay, Mathieu [1 ]
Aublin, Pierre-Louis [2 ]
Pietzuch, Peter [2 ]
Schiavoni, Valerio [3 ]
机构
[1] CSEM, Neuchatel, Switzerland
[2] Imperial Coll London, London, England
[3] Univ Neuchatel, Neuchatel, Switzerland
来源
DISTRIBUTED APPLICATIONS AND INTEROPERABLE SYSTEMS, DAIS 2019 | 2019年 / 11534卷
关键词
Spark; Data streaming; Intel SGX; Medical data; Case-study;
D O I
10.1007/978-3-030-22496-7_6
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Processing sensitive data, such as those produced by body sensors, on third-party untrusted clouds is particularly challenging without compromising the privacy of the users generating it. Typically, these sensors generate large quantities of continuous data in a streaming fashion. Such vast amount of data must be processed efficiently and securely, even under strong adversarial models. The recent introduction in the mass-market of consumer-grade processors with Trusted Execution Environments (TEEs), such as Intel SGX, paves the way to implement solutions that overcome less flexible approaches, such as those atop homomorphic encryption. We present a secure streaming processing system built on top of Intel SGX to showcase the viability of this approach with a system specifically fitted for medical data. We design and fully implement a prototype system that we evaluate with several realistic datasets. Our experimental results show that the proposed system achieves modest overhead compared to vanilla Spark while offering additional protection guarantees under powerful attackers and threat models.
引用
收藏
页码:91 / 107
页数:17
相关论文
共 33 条
[1]  
[Anonymous], 2017, GARTNER LEADING IOT
[2]   Structured Streaming: A Declarative API for Real-Time Applications in Apache Spark [J].
Armbrust, Michael ;
Das, Tathagata ;
Torres, Joseph ;
Yavuz, Burak ;
Zhu, Shixiong ;
Xin, Reynold ;
Ghodsi, Ali ;
Stoica, Ion ;
Zaharia, Matei .
SIGMOD'18: PROCEEDINGS OF THE 2018 INTERNATIONAL CONFERENCE ON MANAGEMENT OF DATA, 2018, :601-613
[3]   Spark SQL: Relational Data Processing in Spark [J].
Armbrust, Michael ;
Xin, Reynold S. ;
Lian, Cheng ;
Huai, Yin ;
Liu, Davies ;
Bradley, Joseph K. ;
Meng, Xiangrui ;
Kaftan, Tomer ;
Franklint, Michael J. ;
Ghodsi, Ali ;
Zaharia, Matei .
SIGMOD'15: PROCEEDINGS OF THE 2015 ACM SIGMOD INTERNATIONAL CONFERENCE ON MANAGEMENT OF DATA, 2015, :1383-1394
[4]  
Barbosa M., 2017, IEEE EDCC
[5]  
Camm AJ, 1996, EUR HEART J, V17, P354
[6]  
Costan V., 2016, Paper 2016/086, DOI DOI 10.1159/000088809
[7]  
Darrow B., GOOGLE IS 1 LINE GET
[8]   Homomorphic Evaluation of the AES Circuit [J].
Gentry, Craig ;
Halevi, Shai ;
Smart, Nigel P. .
ADVANCES IN CRYPTOLOGY - CRYPTO 2012, 2012, 7417 :850-867
[9]   Fully Homomorphic Encryption Using Ideal Lattices [J].
Gentry, Craig .
STOC'09: PROCEEDINGS OF THE 2009 ACM SYMPOSIUM ON THEORY OF COMPUTING, 2009, :169-178
[10]  
Gottel C., 2018, 2018 IEEE 37 S REL D