Single-level integrity and confidentiality protection for distributed shared memory multiprocessors

Single-level integrity and confidentiality protection for distributed shared memory multiprocessors
复制标题

DOI:
10.1109/hpca.2008.4658636
复制
发表时间:
2008-10
期刊:
2008 IEEE 14th International Symposium on High Performance Computer Architecture
影响因子:
--
通讯作者:
Brian Rogers;Chenyu Yan;Siddhartha Chhabra;Milos Prvulović;Yan Solihin
Brian Rogers;Chenyu Yan;Siddhartha Chhabra;Milos Prvulović;Yan Solihin
中科院分区:
其他
文献类型:
--
作者:
Brian Rogers;Chenyu Yan;Siddhartha Chhabra;Milos Prvulović;Yan Solihin

文献摘要

被引文献

相似文献

多处理器计算机系统目前广泛用于商业环境中以运行关键应用程序。这些应用程序通常对客户记录、信用卡号码和财务数据等敏感数据进行操作。因此,这些系统经常成为攻击目标,因为攻击者可以通过窃取或篡改此类数据获得潜在的重大收益。这为通过体系结构支持保护商业多处理器系统中数据的机密性和完整性提供了强大的动力。架构支持能够防范基于软件的攻击,并且对于防范基于硬件的攻击是必要的。在这项工作中,我们提出了一种体系结构机制来确保分布式共享存储多处理器中的数据机密性和完整性,该多处理器利用基于点对点的互连网络。我们的方法比以前在这一领域的工作有所改进,主要是因为我们的方法通过显著减少所需的加密运算量来降低性能开销。评估结果表明,在16处理器DSM系统中,我们的方法可以保护数据的机密性和完整性,平均开销为1.6%,而所有Splash-2应用程序的最大开销仅为7%。
Multiprocessor computer systems are currently widely used in commercial settings to run critical applications. These applications often operate on sensitive data such as customer records, credit card numbers, and financial data. As a result, these systems are the frequent targets of attacks because of the potentially significant gain an attacker could obtain from stealing or tampering with such data. This provides strong motivation to protect the confidentiality and integrity of data in commercial multiprocessor systems through architectural support. Architectural support is able to protect against software-based attacks, and is necessary to protect against hardware-based attacks. In this work, we propose architectural mechanisms to ensure data confidentiality and integrity in Distributed Shared Memory multiprocessors which utilize a point-to-point based interconnection network. Our approach improves upon previous work in this area, mainly in the fact that our approach reduces performance overheads by significantly reducing the amount of cryptographic operations required. Evaluation results show that our approach can protect data confidentiality and integrity in a 16-processor DSM system with an average overhead of 1.6% and a maximum of only 7% across all SPLASH-2 applications.