IP Library › Granted Patent US 12,743,536
Granted Patent B2
US 12,743,536 · App. 18/838,987 · Granted Sep 22, 2026

Security computer device and method for key-value store using log-structured merge-tree

Inventors: Hyungon Moon (Ulsan, KR); Sam Hyuk Noh (Ulsan, KR); Ig Jae Kim (Ulsan, KR); Junghyun Kim (Ulsan, KR); Minu Chung (Ulsan, KR)
Assignee: UNIST (ULSAN NATIONAL INSTITUTE OF SCIENCE AND TECHNOLOGY)
G06F21/6218G06F21/602G06F21/64
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,743,536
App. No.
18/838,987
Granted
Sep 22, 2026
Kind
B2
Abstract

A device according to one embodiment may comprise: a memory including an Enclave Page Cache (EPC) and a partial memory distinguished from the EPC; a storage distinguished from the memory; and a processor, which receives a lookup request including an object key from a user, retrieves the object key from a table stored in the EPC, retrieves the object key from a table of a log-structured merge-tree stored in the storage if the object key is not retrieved from the table stored in the EPC, acquires a reference message authentication code and a value corresponding to the object key from the storage if the object key is retrieved from the target table of the log-structured merge-tree stored in the storage, and verifies the integrity of the value on the basis of the reference message authentication code.

Claims (57)

1 . A method, performed by a processor, comprising:

receiving a lookup request comprising an object key from a user;

retrieving the object key from a table stored in an enclave page cache (EPC) of a memory;

retrieving the object key from a table of a log-structured merge-tree stored in a storage distinct from the memory, when the object key fails to be retrieved from the table stored in the EPC;

obtaining a value corresponding to the object key and a reference message authentication code from the storage, when the object key is retrieved from a target table of the log-structured merge-tree stored in the storage; and

verifying an integrity of the value based on the reference message authentication code;

wherein the obtaining of the value corresponding to the object key and the reference message authentication code from the storage comprises:

obtaining the value corresponding to the object key and the reference message authentication code corresponding to the value from a value block of a target data block, when the object key is retrieved from a key block of the target data block.

2 . The method of claim 1 , wherein the verifying of the integrity of the value based on the reference message authentication code comprises:

obtaining, from the EPC, a target authentication key mapped to the target table among authentication keys mapped to tables of the log-structured merge-tree;

computing a comparative message authentication code for the value, based on the target authentication key obtained from the EPC and the value obtained from the storage; and

verifying the integrity of the value by comparing the computed comparative message authentication code with the obtained reference message authentication code.

3 . The method of claim 1 , wherein the retrieving of the object key from the table of the log-structured merge-tree stored in the storage comprises:

initiating a retrieval of the object key, starting from a lowest level of the log-structured merge-tree stored in the storage;

re-retrieving the object key from a level subsequent to a level at which the retrieval of the object key is being performed, when the object key fails to be retrieved at the level at which the retrieval of the object key is being performed; and

terminating the retrieval of the object key, when the object key is retrieved at the level at which the retrieval of the object key is being performed.

4 . The method of claim 1 , wherein the retrieving of the object key from the table of the log-structured merge-tree stored in the storage comprises:

determining a target data block having a possibility of including the object key, based on an index block of the target table among a plurality of data blocks of the target table of the log-structured merge-tree, the index block indicating a range of an object key included in the plurality of data blocks;

verifying an order of a key block having object keys of a plurality of key-value pairs of the target data block; and

retrieving the object key from the key block, when the order of the key block of the target data block is verified.

5 . The method of claim 4 , wherein the retrieving of the object key from the table of the log-structured merge-tree stored in the storage further comprises:

re-retrieving the object key by changing the target table to a table of a subsequent level of the target table, when the object key fails to be retrieved from the key block of the target data block.

6 . The method of claim 1 , further comprising:

obtaining a reference message authentication code corresponding to the object key and a target authentication key corresponding to a table stored in the EPC from the EPC, when the object key is retrieved from the table stored in the EPC;

obtaining a value corresponding to the object key from a partial memory of the memory distinct from the EPC; and

verifying the integrity of the value based on the reference message authentication code.

7 . The method of claim 6 , wherein the verifying of the integrity of the value based on the reference message authentication code comprises:

computing a comparative message authentication code based on the target authentication key mapped to the table stored in the EPC obtained from the EPC and the value obtained from the partial memory distinct from the EPC; and

verifying the integrity of the value by comparing the computed comparative message authentication code with the reference message authentication code.

8 . A computer program stored in a computer-readable storage medium to execute the method of claim 1 in combination with hardware.

9 . A device comprising:

a memory comprising an enclave page cache (EPC) and a partial memory distinct from the EPC;

a storage distinct from the memory;

a processor configured to receive a lookup request comprising an object key from a user, retrieve the object key from a table stored in the EPC, retrieve the object key from a table of a log-structured merge-tree stored in a storage distinct from the memory, when the object key fails to be retrieved from the table stored in the EPC, obtain a value corresponding to the object key and a reference message authentication code from the storage, when the object key is retrieved from a target table of the log-structured merge-tree stored in the storage, and verify an integrity of the value based on the reference message authentication code;

wherein the processor is configured to:

obtain the value corresponding to the object key and the reference message authentication code corresponding to the value from a value block of a target data block, when the object key is retrieved from a key block of the target data block.

10 . The device of claim 9 , wherein the processor is configured to:

obtain, from the EPC, a target authentication key mapped to the target table among authentication keys mapped to tables of the log-structured merge-tree,

compute a comparative message authentication code for the value, based on the target authentication key obtained from the EPC and the value obtained from the storage, and

verify the integrity of the value by comparing the computed comparative message authentication code with the obtained reference message authentication code.

11 . The device of claim 9 , wherein the processor is configured to:

initiate a retrieval of the object key, starting from a lowest level of the log-structured merge-tree stored in the storage,

re-retrieve the object key from a level subsequent to a level at which the retrieval of the object key is being performed, when the object key fails to be retrieved at the level at which the retrieval of the object key is being performed, and

terminate the retrieval of the object key, when the object key is retrieved at the level at which the retrieval of the object key is being performed.

12 . The device of claim 9 , wherein the processor is configured to:

determine a target data block having a possibility of including the object key, based on an index block of the target table among a plurality of data blocks of the target table of the log-structured merge-tree, the index block indicating a range of an object key included in the plurality of data blocks,

verify an order of a key block having object keys of a plurality of key-value pairs of the target data block, and

retrieve the object key from the key block, when the order of the key block of the target data block is verified.

13 . The device of claim 12 , wherein the processor is configured to:

re-retrieve the object key by changing the target table to a table of a subsequent level of the target table, when the object key fails to be retrieved from the key block of the target data block.

14 . The device of claim 9 , wherein the processor is configured to:

obtain a reference message authentication code corresponding to the object key and a target authentication key corresponding to a table stored in the EPC from the EPC, when the object key is retrieved from the table stored in the EPC,

obtain a value corresponding to the object key from a partial memory of the memory distinct from the EPC, and

verify the integrity of the value based on the reference message authentication code.

15 . The device of claim 14 , wherein the processor is configured to:

compute a comparative message authentication code based on the target authentication key mapped to the table stored in the EPC obtained from the EPC and the value obtained from the partial memory distinct from the EPC, and

verify the integrity of the value by comparing the computed comparative message authentication code with the reference message authentication code.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2024
From: MOON, HYUNGON; NOH, SAM HYUK; KIM, IG JAE; KIM, JUNGHYUN; CHUNG, MINU
To: UNIST (ULSAN NATIONAL INSTITUTE OF SCIENCE AND TECHNOLOGY)
Reel/Frame 069186/0617 →
Priority Claims (1)
KR 10-2022-0021722 · Feb 18, 2022 · national
Continuity (1)
Related Publication 20250139272A1 · May 1, 2025
References Cited (16)
US 11288212B2 · Ki · 2022 [cited by examiner]
US 20210144170A1 · Ganapathy · 2021 [cited by examiner]
US 20220335028A1 · Xue · 2022 [cited by examiner]
CN 113094372A · 2021 [cited by applicant]
CN 113536364A · 2021 [cited by applicant]
KR 1020210078437A · 2021 [cited by applicant]
Bailleu, Maurice, et al., “SPEICHER: Securing LSM-based Key-Value Stores using Shielded Execution”, 17th USENIX Conference on File and Storage Technologies, Feb. 2019. [cited by applicant]
Karapanos, Nikolaos, et al., “Verena: End-to-End Integrity Protection for Web Applications”, 2016 IEEE Symposium on Security and Privacy, 2016. [cited by applicant]
Kim, Igjae, et al., “A Log-Structured Merge Tree-aware Message Authentication Scheme for Persistent Key-Value Stores”, 20th USENIX Conference on File and Storage Technologies, Feb. 2022. [cited by applicant]
Kim, Taehoon, et al., “ShieldStore: Shielded In-memory Key-value Storage with SGX”, 2019 Association for Computing Machinery, Mar. 2019. [cited by applicant]
Li, Kai, et al., “Authenticated Key-Value Stores with Hardware Enclaves”, 2021 Association for Computing Machiner, Dec. 2021. [cited by applicant]
Lu, Lanyue, et al., “WiscKey: Separating Keys from Values in SSD-conscious Storage”, 14th USENIX Conference on File and Storage Technologies, Feb. 2016. [cited by applicant]
Matetic, Sinisa, et al., “ROTE: Rollback Protection for Trusted Execution”, 26th USENIX Security Symposium, Aug. 2017. [cited by applicant]
Parno, Bryan, et al., “Memoir: Practical State Continuity for Protected Modules”, 2011 IEEE Symposium on Security and Privacy, 2011. [cited by applicant]
Yang, Fan, et al., “Aria: Tolerating Skewed Workloads in Secure In-memory Key-value Stores”, Tsinghua University, Apr. 2021. [cited by applicant]
International Search Report of the Korean Intellectual Property Office in PCT application No. PCT/KR2023/002276 issued on May 22, 2023, which is an international application to which this application claims priority. [cited by applicant]