SGX-Enabled Encrypted Cross-Cloud Data Synchronization

Jia Zhao, Yanjing Ren, Jingwei Li, Patrick P. C. Lee · 2025

The increasing adoption of multicloud storage has necessitated the development of efficient cross-cloud data synchronization to improve performance and accessibility across regions, and reduce reliance on single cloud service. Yet, securing cross-cloud synchronization while achieving network efficiency poses challenges. First, ensuring data confidentiality and integrity is difficult due to the diverse encryption configurations and management complexities inherent to different clouds. Second, balancing security and network efficiency is non-trivial, as encryption disrupts content redundancy, complicating efforts to reduce network traffic. We present SeedSync, a system designed to provide secure and efficient cross-cloud data synchronization. SeedSync leverages shielded execution to ensure both security guarantees and network efficiency. It enables encrypted data synchronization without revealing sensitive information and ensures end-to-end data integrity with limited performance overhead using tree-structured integrity protection. It also addresses the dilemma between encryption and network reduction by allowing data to be processed unencrypted within a secure shielded region. Furthermore, inspired by workload characteristics, it speeds up data synchronization by reducing fine-grained network transmission and context switching of SGX. Evaluation on real-world datasets shows that SeedSync achieves up to 8.2 × higher throughput and 5.4 × network reduction existing traffic compared with encrypted synchronization approaches, while incurring limited overhead compared with plaintext synchronization.

Read the paper · More papers on PaperTik