sRDMA - Efficient NIC-based Authentication and Encryption for Remote Direct Memory Access

sRDMA - Efficient NIC-based Authentication and Encryption for Remote Direct Memory Access
复制标题

sRDMA - 用于远程直接内存访问的基于 NIC 的高效身份验证和加密

DOI:
--
复制
发表时间:
2020
期刊:
USENIX Annual Technical Conference
影响因子:
--
通讯作者:
T. Hoefler
T. Hoefler
中科院分区:
--
文献类型:
--
作者:
Konstantin Taranov;Benjamin Rothenberger;A. Perrig;T. Hoefler

文献摘要

被引文献

相似文献

最先进的远程直接内存访问 (RDMA) 技术已被证明很容易受到网络内对手的攻击,因为它们仅通过在每条消息中包含访问令牌来提供较弱的保护形式。网络窃听者可以轻松获取敏感信息并修改绕过数据包,不仅影响保密性,还影响完整性。篡改数据包可能会产生严重后果。例如,当远程更改带有代码的内存页面时,更改数据包内容可以实现远程代码注入。我们提出了 sRDMA,这是一种为 RDMA 提供有效身份验证和加密的协议,以防止信息泄露和消息篡改。 sRDMA 使用对称加密并使用网络接口卡来执行加密操作。此外,我们还提供使用可编程网络适配器的 sRDMA 实现。
State-of-the-art remote direct memory access (RDMA) technologies have shown to be vulnerable against attacks by in-network adversaries, as they provide only a weak form of protection by including access tokens in each message. A network eavesdropper can easily obtain sensitive information and modify bypassing packets, affecting not only secrecy but also integrity. Tampering with packets can have drastic consequences. For example, when memory pages with code are changed remotely, altering packet contents enables remote code injection. We propose sRDMA, a protocol that provides efficient authentication and encryption for RDMA to prevent information leakage and message tampering. sRDMA uses symmetric cryptography and employs network interface cards to perform cryptographic operations. Additionally, we provide an implementation for sRDMA using programmable network adapters.