Secure DIMM: Moving ORAM Primitives Closer to Memory

Secure DIMM: Moving ORAM Primitives Closer to Memory
复制标题

DOI:
10.1109/hpca.2018.00044
复制
发表时间:
2018-03
期刊:
2018 IEEE International Symposium on High Performance Computer Architecture (HPCA)
影响因子:
--
通讯作者:
Ali Shafiee;R. Balasubramonian;Mohit Tiwari;Feifei Li
Ali Shafiee;R. Balasubramonian;Mohit Tiwari;Feifei Li
中科院分区:
其他
文献类型:
--
作者:
Ali Shafiee;R. Balasubramonian;Mohit Tiwari;Feifei Li

文献摘要

被引文献

相似文献

随着越来越多的关键应用转移到云端,迫切需要为数据和计算提供隐私保障。虽然云基础设施容易受到各种攻击,但在本工作中,我们将重点关注一种攻击模型,在该模型中,不受信任的云运营商可以物理访问服务器,并可以监控从处理器插槽中发出的信号。即使数据分组被加密,程序所触及的地址序列也充当信息侧通道。为了消除这种旁通道,不经意的RAM结构已经被研究了几十年,但仍然构成了巨大的开销。在这项工作中,我们认为,通过将一些ORAM功能转移到存储系统中,可以显著减少ORAM开销。我们首先设计了一种使用商用低成本存储器和ASIC作为安全缓冲芯片的安全DIMM(或SDIMM)。然后,我们设计了两个新的ORAM协议,它们利用SDIMM来减少带宽、延迟和每次ORAM访问的能量。在这两种协议中,每个SDIMM负责ORAM树的一部分。每个SDIMM执行许多主内存通道不可见的ORAM操作。通过在系统中安装多个SDIMM,我们能够实现高度并行的ORAM操作。主存通道将其带宽主要用于为CPU请求的块提供服务,并执行常规ORAM所需的许多混洗操作中的一小部分。新协议保证了与路径ORAM相同的健忘性特性。在一组内存密集型工作负载上,与Freecursive Oram相比,我们的两个新Oram协议-独立Oram和Split Oram-能够将性能提高1.9倍,能源提高2.55倍。
As more critical applications move to the cloud, there is a pressing need to provide privacy guarantees for data and computation. While cloud infrastructures are vulnerable to a variety of attacks, in this work, we focus on an attack model where an untrusted cloud operator has physical access to the server and can monitor the signals emerging from the processor socket. Even if data packets are encrypted, the sequence of addresses touched by the program serves as an information side channel. To eliminate this side channel, Oblivious RAM constructs have been investigated for decades, but continue to pose large overheads. In this work, we make the case that ORAM overheads can be significantly reduced by moving some ORAM functionality into the memory system. We first design a secure DIMM (or SDIMM) that uses commodity low-cost memory and an ASIC as a secure buffer chip. We then design two new ORAM protocols that leverage SDIMMs to reduce bandwidth, latency, and energy per ORAM access. In both protocols, each SDIMM is responsible for part of the ORAM tree. Each SDIMM performs a number of ORAM operations that are not visible to the main memory channel. By having many SDIMMs in the system, we are able to achieve highly parallel ORAM operations. The main memory channel uses its bandwidth primarily to service blocks requested by the CPU, and to perform a small subset of the many shuffle operations required by conventional ORAM. The new protocols guarantee the same obliviousness properties as Path ORAM. On a set of memory-intensive workloads, our two new ORAM protocols – Independent ORAM and Split ORAM – are able to improve performance by 1.9x and energy by 2.55x, compared to Freecursive ORAM.