Persist Level Parallelism: Streamlining Integrity Tree Updates for Secure Persistent Memory

Persist Level Parallelism: Streamlining Integrity Tree Updates for Secure Persistent Memory
复制标题

DOI:
10.1109/micro50266.2020.00015
复制
发表时间:
2020-10
期刊:
2020 53rd Annual IEEE/ACM International Symposium on Microarchitecture (MICRO)
影响因子:
--
通讯作者:
Alexander Freij;Shougang Yuan;Huiyang Zhou;Yan Solihin
Alexander Freij;Shougang Yuan;Huiyang Zhou;Yan Solihin
中科院分区:
其他
文献类型:
--
作者:
Alexander Freij;Shougang Yuan;Huiyang Zhou;Yan Solihin

文献摘要

被引文献

相似文献

新兴的非易失性主存储器(NVMM)正迅速集成到计算机系统中。但是,NVMM容易受到潜在的数据残留和重放攻击。已经引入了存储器加密和完整性验证来防止这种数据完整性攻击。但是,它们与越来越多地使用NVMM来提供崩溃可恢复的持久性内存不兼容。最近关于安全NVMM的工作指出,需要原子地持久化数据及其元数据,包括计数器、消息身份验证代码(MAC)和Bonsai Merkle Tree(BMT)。然而,内存持久化模型已被忽视的安全NVMM,这是必不可少的崩溃recoverability.In这项工作中,我们分析了需要确保,以支持安全NVMM崩溃恢复的不变量。我们强调,不坚持这些不变量,以前的研究大大低估了BMT持久性的成本。我们提出了几种优化技术,以减少原子持久更新的开销。提出的优化探索使用流水线,乱序更新和更新合并,同时符合严格或历元持久化模型,分别。我们评估我们的工作,并表明我们提出的优化显着降低安全崩溃可恢复的NVMM的性能开销从720%到只有20%。
Emerging non-volatile main memory (NVMM) is rapidly being integrated into computer systems. However, NVMM is vulnerable to potential data remanence and replay attacks. Memory encryption and integrity verification have been introduced to protect against such data integrity attacks. However, they are not compatible with a growing use of NVMM for providing crash recoverable persistent memory. Recent works on secure NVMM pointed out the need for data and its metadata, including the counter, the message authentication code (MAC), and the Bonsai Merkle Tree (BMT) to be persisted atomically. However, memory persistency models have been overlooked for secure NVMM, which is essential for crash recoverability.In this work, we analyze the invariants that need to be ensured in order to support crash recovery for secure NVMM. We highlight that by not adhering to these invariants, prior research has substantially under-estimated the cost of BMT persistence. We propose several optimization techniques to reduce the overhead of atomically persisting updates to BMTs. The optimizations proposed explore the use of pipelining, out-of-order updates, and update coalescing while conforming to strict or epoch persistency models, respectively. We evaluate our work and show that our proposed optimizations significantly reduce the performance overhead of secure crash-recoverable NVMM from 720% to just 20%.