ASM: An Adaptive Secure Multicore for Co-located Mutually Distrusting Processes

ASM: An Adaptive Secure Multicore for Co-located Mutually Distrusting Processes
复制标题

ASM:用于共置互不信任进程的自适应安全多核

DOI:
10.1145/3587480
复制
发表时间:
2023
影响因子:
1.6
通讯作者:
Khan, Omer
Khan, Omer
中科院分区:
计算机科学3区
文献类型:
--
作者:
Sahni, Abdul Rasheed;Omar, Hamza;Ali, Usman;Khan, Omer

文献摘要

参考文献

相似文献

随着软件和硬件虚拟化程度的不断提高,用户敏感数据的隐私是计算外包的一个基本问题。安全处理器支持可信的执行环境,以保证基于隔离、密封和完整性原则的安全属性。然而,微架构内的共享硬件资源正越来越多地被位于同一位置的对抗软件用于创建基于时序的侧信道攻击。最先进的安全处理器实现了强隔离原语,使共享硬件不受干扰,但遭受频繁的状态清除和资源利用开销,导致性能下降。本文提出了ASM,这是一种自适应的安全多核体系结构,它支持可重构但又高度隔离的执行环境。对于外包的安全关键流程,建议的安全内核和硬件扩展允许使用所有可用的内核执行给定的进程,或者在高度隔离的内核集群上共同执行多个进程。这种时空执行环境是根据进程的资源需求配置的,这样安全处理器就可以减少状态清除开销并最大化硬件资源利用率。
With the ever-increasing virtualization of software and hardware, the privacy of user-sensitive data is a fundamental concern in computation outsourcing. Secure processors enable a trusted execution environment to guarantee security properties based on the principles of isolation, sealing, and integrity. However, the shared hardware resources within the microarchitecture are increasingly being used by co-located adversarial software to create timing-based side-channel attacks. State-of-the-art secure processors implement thestrong isolationprimitive to enable non-interference for shared hardware but suffer from frequent state purging and resource utilization overheads, leading to degraded performance. This article proposes ASM, an adaptive secure multicore architecture that enables a reconfigurable, yet strongly isolated execution environment. For outsourced security-critical processes, the proposed security kernel and hardware extensions allow either a given process to execute using all available cores or co-execute multiple processes on strongly isolated clusters of cores. This spatio-temporal execution environment is configured based on resource demands of processes, such that the secure processor mitigates state purging overheads and maximizes hardware resource utilization.
DOI: 10.1007/11894063_16
发表时间: 2006-10
期刊: --
影响因子: --
作者:
Joseph Bonneau;Ilya Mironov
通讯作者: Joseph Bonneau;Ilya Mironov
IRONHIDE:一种安全多核,可有效缓解交互式应用程序的微架构状态攻击
DOI: 10.1109/hpca47549.2020.00019
发表时间: 2020
期刊: 2020 IEEE International Symposium on High Performance Computer Architecture (HPCA
影响因子: --
作者:
Omar, Hamza;Khan, Omer
通讯作者: Khan, Omer
OPTIMUS:一种以安全为中心的动态硬件分区方案,用于防止微架构状态攻击的处理器
DOI: 10.1109/tc.2020.2996021
发表时间: 2020
影响因子: 3.7
作者:
Omar, Hamza;Dagostino, Brandon;Khan, Omer
通讯作者: Khan, Omer
DOI: 10.48550/arxiv.2306.16093
发表时间: 2023-06
期刊: ArXiv
影响因子: --
作者:
O. Mutlu
通讯作者: O. Mutlu
打破 Oblivious-RAM 带宽墙
DOI: 10.1109/iccd.2018.00026
发表时间: 2018
期刊: 2018 IEEE 36th International Conference on Computer Design (ICCD
影响因子: --
作者:
Omar, Hamza;Haider, Syed Kamran;Ren, Ling;van Dijk, Marten;Khan, Omer
通讯作者: Khan, Omer