Secure Hardware Kernels Execution in CPU+FPGA Heterogeneous Cloud

Secure Hardware Kernels Execution in CPU+FPGA Heterogeneous Cloud
复制标题

CPU FPGA 异构云中的安全硬件内核执行

DOI:
10.1109/fpt.2018.00035
复制
发表时间:
2018
期刊:
2018 International Conference on Field-Programmable Technology (FPT)
影响因子:
--
通讯作者:
C. Bobda
C. Bobda
中科院分区:
--
文献类型:
--
作者:
Festus Hategekimana;Joel Mandebi Mbongue;Md Jubaer Hossain Pantho;C. Bobda

文献摘要

被引文献

相似文献

在本文中,我们提出了一个新的安全框架,允许在异构云系统中相互不信任的FPGA加速器的受控共享和隔离执行。所提出的框架使得在云计算机中的FPGA中运行的加速器能够在运行时透明地继承调用它们的虚拟机进程的软件安全策略。此功能允许系统安全策略执行机制将在管理程序级别表示的访问控制权限边界向下传播到各个FPGA加速器。此外,我们提出了一个软件/硬件原型实现的建议的安全框架,它可以很容易地被透明地集成在虚拟机软件栈中运行在今天的基于云的系统。实验结果表明,我们提出的框架提供了安全的硬件执行与可忽略不计的执行开销上的来宾虚拟机应用程序。
In this paper, we present a new security framework which allows controlled sharing and isolated execution of mutually distrusted FPGA-accelerators in heterogeneous cloud systems. The proposed framework enables the accelerators running in FPGAs in cloud computers to transparently inherit at run-time, software security policies of the virtual machines processes calling them. This capability allows system security policies enforcement mechanism to propagate access control privilege boundaries expressed at the hypervisor level, down to individual FPGA-accelerators. Furthermore, we present a software/hardware prototype implementation of the proposed security framework, showing that it can easily be transparently integrated within the virtual machine software stacks that run in today's cloud-based systems. Experimentation results show our proposed framework provides secure hardware execution with negligible execution overhead on guest VMs applications.