A Case for Near Data Security ∗
A Case for Near Data Security ∗
复制标题
近数据安全案例*
DOI:
--
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
R. Balasubramonian
中科院分区:
文献类型:
--
作者:
Akhila Gundu;Ali Shafiee Ardestani;Manjunath Shevgoor;R. Balasubramonian
Security is a vital requirement in many high-end systems, es pecially those that make up modern cloud infrastructures. C loud systems are vulnerable to many attacks, including those by u ntrusted cloud operators that have access to physical hardwa e. Memory authentication confirms that an attacker is not modif ying the values being returned by the memory system. But it impose s a severe memory bandwidth overhead that limits its adoption in highly cost-constrained cloud systems. The ideas proposed in this position paper attempt to lower these overheads and mak e memory authentication more palatable for cloud systems. While near data processing has been explored to improve application performance and power efficiency, it has not been l veraged to improve auxiliary operations for security. This pap er argues that logic for memory authentication should be placed o n the memory module itself so it has access to significantly hig her bandwidth. To preserve security guarantees, the near data p rocessor and its link to the main host processor have to be made secure. We describe this design and estimate the first-order potential for benefit.