SecPB: Architectures for Secure Non-Volatile Memory with Battery-Backed Persist Buffers

SecPB: Architectures for Secure Non-Volatile Memory with Battery-Backed Persist Buffers
复制标题

DOI:
10.1109/hpca56546.2023.10071082
复制
发表时间:
2023-02
期刊:
2023 IEEE International Symposium on High-Performance Computer Architecture (HPCA)
影响因子:
--
通讯作者:
Alexander Freij;Huiyang Zhou;Yan Solihin
Alexander Freij;Huiyang Zhou;Yan Solihin
中科院分区:
其他
文献类型:
--
作者:
Alexander Freij;Huiyang Zhou;Yan Solihin

文献摘要

相似文献

持久内存 (PM) 中存储的数据的持久性使数据面临潜在的数据泄漏攻击。最近的研究已经确定了崩溃可恢复的安全 PM 的要求,但没有考虑片上持久性域扩展以包括缓存层次结构的最新趋势。在本文中,我们探索了这个设计空间并确定了性能和能源优化机会。我们提出了安全持久缓冲区(SecPB),这是一种电池支持的持久结构,可将安全数据持久性点从内存控制器移至更靠近核心的位置。我们重新审视了 PM 中数据保护的基本原理,并展示了如何延迟生成安全元数据的各种子集,同时仍然保证崩溃可恢复性和完整性验证。我们分析了保护 PM 所需的元数据依赖链,并揭示了优化机会,使 SecPB 能够将性能开销降低高达 32.8 倍,在合理的电池容量下观察到的平均性能开销低至 1.3%。
The durability of data stored in persistent memory (PM) exposes data to potentially data leakage attacks. Recent research has identified the requirements for crash recoverable secure PM, but do not consider recent trends of the persistency domain extending on-chip to include cache hierarchies. In this paper, we explore this design space and identify performance and energy optimization opportunities.We propose secure persistent buffers (SecPB), a battery-backed persistent structure that moves the point of secure data persistency from the memory controller closer to the core. We revisit the fundamentals of how data in PM is secured and show how various subsets of security metadata can be generated lazily while still guaranteeing crash recoverability and integrity verification. We analyze the metadata dependency chain required in securing PM and expose optimization opportunities that allow for SecPB to reduce performance overheads by up to 32.8×, with average performance overheads as low as 1.3% observed for reasonable battery capacities.