How to build a trusted database system on untrusted storage
Umesh Maheshwari, Radek Vingralek, William H. Shapiro · 2000
So me emerging applications require programs to main-tain sensitive state o n untrusted hosts. This paper pre-sen ts the architecture and implementation of a trusted d atabase system, TDB, which leverages a small amount of trusted storage to protect a scalable amount of un-tru sted storage. The database is encrypted and validated against a collision-resistant hash kept in trusted storage, s o untrusted programs cannot read the database or mod-if y it undetectably. TDB integrates encryption and hash-ing with a low-level data model, which protects data and metadata uniformly, unlike systems built on top of a co nventional database system. The implementation ex-p loits synergies between hashing and log-structured storag e. Preliminary performance results show that TDB outperforms an off-the-shelf embedded database s ystem, thus supporting the suitability of the TDB archi-tectu re. 1