A Case for Near Data Security ∗

A Case for Near Data Security ∗
复制标题

近数据安全案例*

DOI:
--
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
R. Balasubramonian
R. Balasubramonian
中科院分区:
--
文献类型:
--
作者:
Akhila Gundu;Ali Shafiee Ardestani;Manjunath Shevgoor;R. Balasubramonian

文献摘要

被引文献

相似文献

安全性是许多高端系统的重要要求,尤其是构成现代云基础设施的系统。云系统容易受到许多攻击,包括由有权访问物理硬件的不受信任的云运营商发起的攻击。内存身份验证确认攻击者没有修改内存系统返回的值。但它会带来严重的内存带宽开销,限制了其在成本高度受限的云系统中的采用。本立场文件中提出的想法试图降低这些开销并使内存身份验证更适合云系统。虽然人们已经探索近数据处理来提高应用程序性能和能效,但尚未利用它来改进辅助操作以确保安全。本文认为,内存认证逻辑应该放置在内存模块本身上,这样它就可以访问显着更高的带宽。为了保证安全,必须保证近端数据处理器及其与主处理器的链接的安全。我们描述了这种设计并估计了一阶潜在的效益。
Security is a vital requirement in many high-end systems, es pecially those that make up modern cloud infrastructures. C loud systems are vulnerable to many attacks, including those by u ntrusted cloud operators that have access to physical hardwa e. Memory authentication confirms that an attacker is not modif ying the values being returned by the memory system. But it impose s a severe memory bandwidth overhead that limits its adoption in highly cost-constrained cloud systems. The ideas proposed in this position paper attempt to lower these overheads and mak e memory authentication more palatable for cloud systems. While near data processing has been explored to improve application performance and power efficiency, it has not been l veraged to improve auxiliary operations for security. This pap er argues that logic for memory authentication should be placed o n the memory module itself so it has access to significantly hig her bandwidth. To preserve security guarantees, the near data p rocessor and its link to the main host processor have to be made secure. We describe this design and estimate the first-order potential for benefit.