Confidential databases (CDBs) are essential for enabling secure queries over sensitive data in untrusted cloud environments using confidential computing hardware. While adoption is growing, widespread deployment is hindered by high performance overhead from frequent synchronous cryptographic operations, which causes significant computational and memory bottlenecks. We present FEDB, a novel CDB design that removes cryptographic operations from the critical path. FEDB leverages crypto-free mappings, which maintain data-independent identifiers within the database while securely mapping them to plaintext secrets in a trusted domain. This paradigm shift reduces the runtime overhead by up to 78.0 times on industry-standard benchmarks including TPC-C and TPC-H.
翻译:机密数据库(CDB)对于在不可信云环境中利用机密计算硬件对敏感数据执行安全查询至关重要。尽管其应用日益增长,但频繁同步加密操作带来的高性能开销造成了显著的计算和内存瓶颈,阻碍了其广泛部署。我们提出FEDB,一种创新的CDB设计,将加密操作从关键路径中移除。FEDB利用无加密映射,在数据库内维护与数据无关的标识符,同时将其安全映射至可信域中的明文秘密。这一范式转变在包括TPC-C和TPC-H在内的行业标准基准测试中,将运行时开销降低了高达78.0倍。