D-Shield: Enabling Processor-side Encryption and Integrity Verification for Secure NVMe Drives

D-Shield: Enabling Processor-side Encryption and Integrity Verification for Secure NVMe Drives
复制标题

DOI:
10.1109/hpca56546.2023.10070924
复制
发表时间:
2023-02
期刊:
2023 IEEE International Symposium on High-Performance Computer Architecture (HPCA)
影响因子:
--
通讯作者:
Md Hafizul Islam Chowdhuryy;Myoungsoo Jung;F. Yao;Amro Awad
Md Hafizul Islam Chowdhuryy;Myoungsoo Jung;F. Yao;Amro Awad
中科院分区:
其他
文献类型:
--
作者:
Md Hafizul Islam Chowdhuryy;Myoungsoo Jung;F. Yao;Amro Awad

文献摘要

相似文献

确保存储在存储磁盘中的数据的机密性和完整性对于保护用户的敏感和私人数据至关重要。基于硬件的攻击的最新发展已经激发了不仅在静态而且在传输中保护存储数据的需求。不幸的是,现有的技术,如基于软件的磁盘加密和基于硬件的自加密磁盘无法提供这种全面的保护,在今天的对抗设置。随着NVMe固态硬盘的发展,超低I/O延迟和高并行性成为其发展的趋势,构建一个存储子系统,确保数据存储在快速磁盘中的安全性而不牺牲其性能至关重要。在本文中,我们提出了D-Shield,一个处理器端安全框架,以低开销全面保护NVMe存储数据的机密性和完整性。D-Shield集成了一个新的DMA拦截引擎,允许处理器执行安全元数据维护和数据保护,而无需对NVMe协议和NVMe磁盘进行任何修改。我们进一步提出了优化的D-Shield方案,可以最大限度地减少跨安全域数据传输的解密/重新加密开销,并利用存储元数据的高效内存中缓存来进一步提高系统性能。我们实现了D-Shield原型,并使用一组合成和真实世界的基准来评估其功效。我们的研究结果表明,与基于软件的保护方案相比,D-Shield可以为I/O密集型工作负载带来高达17倍的加速。对于服务器级数据库和图形应用程序,D-Shield的吞吐量比基于软件的加密和完整性检查机制高出96%,同时提供强大的安全保障,防止片外存储攻击。同时,D-Shield在实际工作负载上的有效性能开销仅为6%,并且具有适度的存储元数据开销和片上硬件成本。
Ensuring the confidentiality and integrity of data stored in storage disks is essential to protect users’ sensitive and private data. Recent developments of hardware-based attacks have motivated the need to secure storage data not only at rest but also in transit. Unfortunately, existing techniques such as software-based disk encryption and hardware-based self-encrypting disks fail to offer such comprehensive protection in today’s adversarial settings. With the advances of NVMe SSDs promising ultralow I/O latencies and high parallelism, architecting a storage subsystem that ensures the security of data storage in fast disks without adversely sacrificing their performance is critical.In this paper, we present D-Shield, a processor-side secure framework to holistically protect NVMe storage data confidentiality and integrity with low overheads. D-Shield integrates a novel DMA Interception Engine that allows the processor to perform security metadata maintenance and data protection without any modification to the NVMe protocol and NVMe disks. We further propose optimized D-Shield schemes that minimize decryption/re-encryption overheads for data transfer crossing security domains and utilize efficient in-memory caching of storage metadata to further boost system performance. We implement D-Shield prototypes and evaluate their efficacy using a set of synthetic and real-world benchmarks. Our results show that D-Shield can introduce up to 17× speedup for I/O intensive workloads compared to software-based protection schemes. For server-class database and graph applications, D-Shield achieves up to 96% higher throughput over software-based encryption and integrity checking mechanisms, while providing strong security guarantee against off-chip storage attacks. Meanwhile, D-Shield shows only 6% overhead on effective performance on real-world workloads and has modest in-storage metadata overhead and on-chip hardware cost.