LITE: a low-cost practical inter-operable GPU TEE

LITE: a low-cost practical inter-operable GPU TEE
复制标题

DOI:
10.1145/3524059.3532361
复制
发表时间:
2022-06
期刊:
Proceedings of the 36th ACM International Conference on Supercomputing
影响因子:
--
通讯作者:
Ardhi Wiratama Baskara Yudha;J. Meyer;Shougang Yuan;Huiyang Zhou;Yan Solihin
Ardhi Wiratama Baskara Yudha;J. Meyer;Shougang Yuan;Huiyang Zhou;Yan Solihin
中科院分区:
其他
文献类型:
--
作者:
Ardhi Wiratama Baskara Yudha;J. Meyer;Shougang Yuan;Huiyang Zhou;Yan Solihin

文献摘要

被引文献

相似文献

随着GPU在云环境中的使用越来越多,对GPU可信执行环境(tee)的需求越来越大。然而,当前的建议要么忽略内存安全性(即,不加密内存),要么从主机TEE强加一个单独的内存加密域,导致与主机通信数据的速度非常慢。在本文中,我们提出了一种灵活的GPU内存加密设计,称为LITE,它依赖于小型架构支持下的软件内存加密。LITE的灵活性允许GPU TEE与CPU共同设计,以创建统一的加密域。我们展示了GPU应用程序可以适应使用LITE加密api而无需进行重大更改。通过各种优化,我们表明LITE中的软件内存加密对于常规基准测试可以产生可以忽略不计的性能开销(1.1%),对于不定期基准测试仍然可以产生可接受的开销(56%)。
There is a strong need for GPU trusted execution environments (TEEs) as GPU is increasingly used in the cloud environment. However, current proposals either ignore memory security (i.e., not encrypting memory) or impose a separate memory encryption domain from the host TEE, causing a very substantial slowdown for communicating data from/to the host. In this paper, we propose a flexible GPU memory encryption design called LITE that relies on software memory encryption aided by small architecture support. LITE's flexibility allows GPU TEE to be co-designed with CPU to create a unified encryption domain. We show that GPU applications can be adapted to the use of LITE encryption APIs without major changes. Through various optimizations, we show that software memory encryption in LITE can produce negligible performance overheads (1.1%) for regular benchmarks and still-acceptable overheads (56%) for irregular benchmarks.