IceClave: A Trusted Execution Environment for In-Storage Computing

IceClave: A Trusted Execution Environment for In-Storage Computing
复制标题

DOI:
10.1145/3466752.3480109
复制
发表时间:
2021-09
期刊:
MICRO-54: 54th Annual IEEE/ACM International Symposium on Microarchitecture
影响因子:
--
通讯作者:
Luyi Kang;Y. Xue;Weiwei Jia;Xiaohao Wang;Jongryool Kim;Changhwan Youn;Myeong Joon Kang;Hyung Jin Li
Luyi Kang;Y. Xue;Weiwei Jia;Xiaohao Wang;Jongryool Kim;Changhwan Youn;Myeong Joon Kang;Hyung Jin Li
中科院分区:
其他
文献类型:
--
作者:
Luyi Kang;Y. Xue;Weiwei Jia;Xiaohao Wang;Jongryool Kim;Changhwan Youn;Myeong Joon Kang;Hyung Jin Li

文献摘要

相似文献

使用现代固态硬盘(SSD)的存储计算使开发人员能够将程序从主机卸载到SSD。它已被证明是缓解I/O瓶颈的有效方法。为了促进存储中计算,已经提出了许多框架。然而,很少有人把仓储安全作为第一公民来对待。具体来说,由于现代SSD控制器没有可信的执行环境,卸载(恶意)程序可能会窃取,修改甚至破坏存储在SSD中的数据。在本文中,我们首先调查的攻击,可以进行卸载存储程序。为了抵御这些攻击,我们建立了一个轻量级的可信执行环境,命名为IceClave存储计算。IceClave通过TrustZone扩展实现了存储程序与闪存管理功能之间的安全隔离,包括闪存地址转换、数据访问控制和垃圾收集。IceClave还通过以低开销强制执行存储DRAM的内存完整性验证来实现存储程序之间的安全隔离。为了保护从闪存芯片加载的数据,IceClave在闪存控制器中开发了一种轻量级的数据加密/解密机制。我们用完整的系统模拟器开发IceClave。我们评估IceClave与各种数据密集型应用程序,如数据库。与最先进的存储计算方法相比,IceClave仅引入了7.6%的性能开销,同时以最小的硬件成本在SSD控制器中实施安全隔离。IceClave仍然保持了存储计算的性能优势,其性能比传统的基于主机的可信计算方法高出2.31倍。
In-storage computing with modern solid-state drives (SSDs) enables developers to offload programs from the host to the SSD. It has been proven to be an effective approach to alleviate the I/O bottleneck. To facilitate in-storage computing, many frameworks have been proposed. However, few of them treat the in-storage security as the first citizen. Specifically, since modern SSD controllers do not have a trusted execution environment, an offloaded (malicious) program could steal, modify, and even destroy the data stored in the SSD. In this paper, we first investigate the attacks that could be conducted by offloaded in-storage programs. To defend against these attacks, we build a lightweight trusted execution environment, named IceClave for in-storage computing. IceClave enables security isolation between in-storage programs and flash management functions that include flash address translation, data access control, and garbage collection, with TrustZone extensions. IceClave also achieves security isolation between in-storage programs by enforcing memory integrity verification of in-storage DRAM with low overhead. To protect data loaded from flash chips, IceClave develops a lightweight data encryption/decryption mechanism in flash controllers. We develop IceClave with a full system simulator. We evaluate IceClave with a variety of data-intensive applications such as databases. Compared to state-of-the-art in-storage computing approaches, IceClave introduces only 7.6% performance overhead, while enforcing security isolation in the SSD controller with minimal hardware cost. IceClave still keeps the performance benefit of in-storage computing by delivering up to 2.31 × better performance than the conventional host-based trusted computing approach.