A Case for SmartNIC-accelerated Private Communication

A Case for SmartNIC-accelerated Private Communication
复制标题

SmartNIC 加速的私人通信案例

DOI:
--
复制
发表时间:
2020
期刊:
Asia-Pacific Workshop on Networking
影响因子:
--
通讯作者:
KyoungSoo Park
KyoungSoo Park
中科院分区:
--
文献类型:
--
作者:
Duckwoo Kim;Seungeon Lee;KyoungSoo Park

文献摘要

被引文献

相似文献

传输层安全(TLS)已成为现代Internet中专用网络通信的关键组成部分。虽然最近CPU的进步大大提高了数据加密性能,但TLS密钥交换仍然是短期事务的瓶颈。专用硬件加密加速器承诺良好的性能,但由于其固有的异步处理架构,它们通常需要对应用程序进行侵入性修改。在本文中,我们探讨了一种潜在的卸载TLS握手到网络接口卡(NIC)与硬件加密加速器。我们设想了一种用于TCP的分割TLS处理架构,该架构处理NIC上的TCP连接设置和TLS握手,同时在基于CPU的主机堆栈中执行其余操作。我们提出了我们的设计原理,并讨论了一系列挑战,实现我们的目标。我们在现有SmartNIC上的概念验证实现显示了一个有希望的结果,因为它带来了比单个CPU核心高5.9倍的吞吐量提升。
Transport Layer Security (TLS) has become a key building block for private network communication in modern Internet. While recent advancement of CPU has substantially improved the data encryption performance, TLS key exchange still remains the bottleneck for short-lived transactions. Dedicated hardware crypto accelerators promise good performance, but they often require invasive modification of the application due to its inherent architecture of asynchronous processing. In this paper, we explore a potential for offloading TLS handshake to network interface cards (NICs) with a hardware crypto accelerator. We envision a split TLS processing architecture for TCP that handles TCP connection setup and TLS handshake on NIC while carrying out the remaining operations in the CPU-based host stack. We present our rationale for the design and discuss a set of challenges towards our goal. Our proof-of-concept implementation on existing SmartNIC shows a promising result as it brings 5.9x throughput improvement than that of a single CPU core.