S-Blocks: Lightweight and Trusted Virtual Security Function With SGX

S-Blocks: Lightweight and Trusted Virtual Security Function With SGX
复制标题

DOI:
10.1109/tcc.2020.2985045
复制
发表时间:
2022-04
影响因子:
6.5
通讯作者:
Juan Wang;Shirong Hao;Hongxin Hu;Bo Zhao;Hongda Li;Wenhui Zhang;Jun Xu;Peng Liu;Jing Ma
Juan Wang;Shirong Hao;Hongxin Hu;Bo Zhao;Hongda Li;Wenhui Zhang;Jun Xu;Peng Liu;Jing Ma
中科院分区:
计算机科学2区
文献类型:
--
作者:
Juan Wang;Shirong Hao;Hongxin Hu;Bo Zhao;Hongda Li;Wenhui Zhang;Jun Xu;Peng Liu;Jing Ma

文献摘要

相似文献

尽管具有可扩展性和灵活性等优势,安全功能虚拟化(SFV)自身的安全性却引发了担忧。为增强SFV的安全性,一种有前景的方法是在软件防护扩展(SGX)飞地中运行现成安全软件的关键组件。然而,由于难以将组件从整体式安全功能中分离出来,以及在飞地中执行它们的成本过高,这一想法几乎不具可行性。在本文中,我们提出了S - 模块(S - Blocks)架构,它能以高效的方式对虚拟安全功能(VSF)进行模块化,并使用SGX保护关键模块。S - 模块将VSF分解为可信模块和不可信模块,并系统地提供专用应用程序编程接口(API)。只有关键的VSF模块使用飞地进行加固。此外,为解决安全功能扩展中的状态一致性和安全迁移问题,我们设计了一种细粒度的状态同步和迁移机制,以确保VSF无损失、保持顺序且状态安全。为证明我们方法的有效性,我们在真实的Skylake平台上使用Fast - Click对S - 模块进行原型设计,并基于S - 模块架构实现了三种关键类型的虚拟安全功能。我们的评估结果表明,S - 模块在保护VSF时仅产生可管理的性能开销,以及低延迟和资源消耗。
Despite the advantages of scalability and flexibility, Security Function Virtualization (SFV) raises concerns about its own security. To enhance the security of SFV, a promising approach is to run critical components of off-the-shelf security software inside Software Guard Extensions (SGX) enclaves. This idea, however, is hardly practical due to the difficulty of detaching components from the monolithic security function and the unacceptable cost of executing them inside enclaves. In this article, we propose S-Blocks, an architecture to modularize virtual security functions (VSFs) and protect crucial modules with SGX in an efficient manner. S-Blocks decomposes VSFs into trusted and untrusted modules and provides dedicated APIs systematically. Only crucial VSF modules are hardened with enclaves. Furthermore, aiming at addressing state consistency and secure migration issues of security function scaling, we design a fine-grained state synchronization and migration mechanism to ensure loss-free, order-preserving, and state security for VSFs. To demonstrate the effectiveness of our approach, we prototype S-Blocks using Fast-Click on a real Skylake platform and implement three critical types of virtual security functions based on the S-Blocks architecture. Our evaluation results show that S-Blocks only imposes a manageable performance overhead, and low latency and resource consumption when protecting VSFs.