Using Trusted Execution Environments for Secure Stream Processing of Medical Data (Case Study Paper)

被引:10
作者
Segarra, Carlos [1 ]
Delgado-Gonzalo, Ricard [1 ]
Lemay, Mathieu [1 ]
Aublin, Pierre-Louis [2 ]
Pietzuch, Peter [2 ]
Schiavoni, Valerio [3 ]
机构
[1] CSEM, Neuchatel, Switzerland
[2] Imperial Coll London, London, England
[3] Univ Neuchatel, Neuchatel, Switzerland
来源
DISTRIBUTED APPLICATIONS AND INTEROPERABLE SYSTEMS, DAIS 2019 | 2019年 / 11534卷
关键词
Spark; Data streaming; Intel SGX; Medical data; Case-study;
D O I
10.1007/978-3-030-22496-7_6
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Processing sensitive data, such as those produced by body sensors, on third-party untrusted clouds is particularly challenging without compromising the privacy of the users generating it. Typically, these sensors generate large quantities of continuous data in a streaming fashion. Such vast amount of data must be processed efficiently and securely, even under strong adversarial models. The recent introduction in the mass-market of consumer-grade processors with Trusted Execution Environments (TEEs), such as Intel SGX, paves the way to implement solutions that overcome less flexible approaches, such as those atop homomorphic encryption. We present a secure streaming processing system built on top of Intel SGX to showcase the viability of this approach with a system specifically fitted for medical data. We design and fully implement a prototype system that we evaluate with several realistic datasets. Our experimental results show that the proposed system achieves modest overhead compared to vanilla Spark while offering additional protection guarantees under powerful attackers and threat models.
引用
收藏
页码:91 / 107
页数:17
相关论文
共 33 条
[11]  
Gueron S., 2016, Cryptology ePrint Archive, Paper 2016/204
[12]  
Havet A., 2017, P 11 ACM INT C DISTR, P124
[13]   SABER: Window-Based Hybrid Stream Processing for Heterogeneous Architectures [J].
Koliousis, Alexandros ;
Weidlich, Matthias ;
Fernandez, Raul Castro ;
Wolf, Alexander L. ;
Costa, Paolo ;
Pietzuch, Peter .
SIGMOD'16: PROCEEDINGS OF THE 2016 INTERNATIONAL CONFERENCE ON MANAGEMENT OF DATA, 2016, :555-569
[14]  
Kumar A., 2016, SIGNAL IMAGE PROCESS, DOI [10.1007/978-981-10-0690-6, DOI 10.1007/978-981-10-0690-6]
[15]  
McKeen F., 2013, HARDWARE ARCHITECTUR
[16]  
Miao H., 2017, USENIX ATC 2017
[17]  
Paillier P, 1999, LECT NOTES COMPUT SC, V1592, P223
[18]  
Parak J, 2015, IEEE ENG MED BIO, P8099, DOI 10.1109/EMBC.2015.7320273
[19]  
Puthal D, 2015, 2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, P246, DOI [10.1109/Trustcom.2015.381, 10.1109/Trustcom-2015.381]
[20]  
Renevey P, 2018, IEEE ENG MED BIO, P2861, DOI 10.1109/EMBC.2018.8512881