TruShare: Confidential Key-Value Store for Untrusted Environments
Aghiles Ait Messaoud, Sonia Ben Mokhtar, Anthony Simonet-Boulogne · 2025
Key-Value Stores (KVSs), commonly used for storing sensitive data, face significant security challenges when deployed in untrusted cloud environments. These environments are susceptible to various types of attacks exploiting a compromised OS or running a side-channel attacks. To protect sensitive data from these types of attacks distributed TEE-based KVSs have been proposed. However, these solutions are still vulnerable to side channel attacks that may compromise any node and leak all its data at once. Active defense mechanisms against side channel attacks, such as Oblivious RAM, are impractical to deploy due to their significant performance overhead or the requirement for additional hardware (e.g., FPGA). Consequently, these defense mechanisms are often skipped in favor of performance in most existing TEE-based KVSs, which weakens their security. To address this issue, we present TruShare, a practical distributed in-memory KVS that integrates TEEs (Intel SGX) and Shamir Secret Sharing (SS) to provide security against high-privileged spywares while tolerating side-channel attacks on a fraction of storage nodes, without requiring costly active defense mechanisms. We implemented TruShare and evaluated its performance using 25 Microsoft Azure VMs. Compared to its closest competitors, TruShare considers a stronger threat model while providing more practical performance than solutions relying on active defense mechanisms against side-channel attacks.