Making secure processors OS- and performance-friendly

Making secure processors OS- and performance-friendly
复制标题

使安全处理器对操作系统和性能友好

DOI:
10.1145/1498690.1498691
复制
发表时间:
2009
期刊:
ACM Trans. Archit. Code Optim.
影响因子:
--
通讯作者:
Milos Prvulović
Milos Prvulović
中科院分区:
--
文献类型:
--
作者:
Siddhartha Chhabra;Brian Rogers;Yan Solihin;Milos Prvulović

文献摘要

被引文献

相似文献

在当今的数字世界中,计算机安全问题变得越来越重要。特别是,研究人员已经提出了安全处理器的设计,利用基于硬件的存储器加密和完整性验证,以保护隐私和计算的完整性,甚至从复杂的物理攻击。然而,目前提出的计划仍然受到阻碍的问题,使他们不切实际的使用在今天的计算机系统:缺乏虚拟存储器和进程间通信的支持,以及过多的存储和性能开销。在这篇文章中,我们提出了(1)地址独立种子加密(AISE),一种基于计数器模式的存储器加密方案,使用一种新的种子组合,和(2)盆景Merkle树(BMT),一种新的基于Merkle树的存储器完整性验证技术,以消除这些系统和性能问题与以前的计数器模式存储器加密和Merkle树完整性验证方案。我们提出了一个定性的讨论和定量的分析,以说明我们的技术的优势,在复杂性,可行性,性能和存储方面,以前提出的方法。我们的研究结果表明,AISE+BMT减少了以前的内存加密和完整性验证计划的开销从12%到2%,平均为单线程的基准测试单处理器系统,从15%到4%,同时消除关键的系统级问题的多核系统上的协同调度基准测试。
In today's digital world, computer security issues have become increasingly important. In particular, researchers have proposed designs for secure processors that utilize hardware-based memory encryption and integrity verification to protect the privacy and integrity of computation even from sophisticated physical attacks. However, currently proposed schemes remain hampered by problems that make them impractical for use in today's computer systems: lack of virtual memory and Inter-Process Communication support as well as excessive storage and performance overheads. In this article, we propose (1) address independent seed encryption (AISE), a counter-mode-based memory encryption scheme using a novel seed composition, and (2) bonsai Merkle trees (BMT), a novel Merkle tree-based memory integrity verification technique, to eliminate these system and performance issues associated with prior counter-mode memory encryption and Merkle tree integrity verification schemes. We present both a qualitative discussion and a quantitative analysis to illustrate the advantages of our techniques over previously proposed approaches in terms of complexity, feasibility, performance, and storage. Our results show that AISE+BMT reduces the overhead of prior memory encryption and integrity verification schemes from 12% to 2% on average for single-threaded benchmarks on uniprocessor systems, and from 15% to 4% for coscheduled benchmarks on multicore systems while eliminating critical system-level problems.