Efficient Distributed Secure Memory with Migratable Merkle Tree
Erhu Feng, Dong Du, Yubin Xia, Haibo Chen
Abstract
Hardware-assisted enclaves with memory encryption have been widely adopted in the prevailing architectures, e.g., Intel SGX/TDX, AMD SEV, ARM CCA, etc. However, existing enclave designs fall short in supporting efficient cooperation among cross-node enclaves (i.e., multi-machines) because the range of hardware memory protection is within a single node. A naive approach is to leverage cryptography at the application level and transfer data between nodes through secure channels (e.g., SSL). However, it incurs orders of magnitude costs due to expensive encryption/decryption, especially for distributed applications with large data transfer, e.g., MapReduce and graph computing. A secure and efficient mechanism of distributed secure memory is necessary but still missing.This paper proposes Migratable Merkle Tree (MMT), a design enabling efficient distributed secure memory to support distributed confidential computing. MMT sets up an integrity forest for distributed memory on multiple nodes. It allows an enclave to securely delegate an MMT closure, which contains both data and metadata of a subtree, to a remote enclave. By reusing the memory encryption mechanisms of existing enclaves, our design achieves secure data transfer without software re-encryption. We have implemented a prototype of MMT and a trusted firmware for management, and further applied MMT to real-world distributed applications. The evaluation results show that compared with existing systems using the AES-NI instruction, MMT can achieve up to 13x speedup on data transferring, and gain 12% 58% improvement on the end-to-end performance of MapReduce and PageRank.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers5
- TensorTEE: Unifying Heterogeneous TEE Granularity for Efficient Secure Collaborative Tensor ComputingHusheng Han, Xinyao Zheng, Yuanbo Wen, Yifan Hao et al.ASPLOS 2024 · 12 citations
- sIOPMP: Scalable and Efficient I/O Protection for TEEsErhu Feng, Dahu Feng, Dong Du, Yubin Xia et al.ASPLOS 2024 · 10 citations
- Accelerating Extra Dimensional Page Walks for Confidential ComputingDong Du, Bicheng Yang, Yubin Xia, Haibo ChenMICRO 2023 · 7 citations
- Efficient Security Support for CXL Memory through Adaptive Incremental Offloaded (Re-)EncryptionChuanhan Li, Jishen Zhao, Yuanchao XuMICRO 2025 · 5 citations
- Unified Memory Protection with Multi-granular MAC and Integrity Tree for Heterogeneous ProcessorsSunho Lee, Seonjin Na, Jeongwon Choi, Jinwon Pyo et al.ISCA 2025 · 2 citations
Related papers
- Scalable Memory Protection in the PENGLAI EnclaveErhu Feng, Xu Lu, Dong Du, Bicheng Yang et al.OSDI 2021 · 126 citations
- vSGX: Virtualizing SGX Enclaves on AMD SEVShixuan Zhao, Mengyuan Li, Yinqian Zhang, Zhiqiang LinS&P 2022 · 32 citations
- Accelerating Encrypted Deduplication via SGXYanjing Ren, Jingwei Li, Zuoru Yang, Patrick P. C. Lee et al.USENIX ATC 2021 · 50 citations
- MPTEE: bringing flexible and efficient memory protection to Intel SGXWenjia Zhao, Kangjie Lu, Yong Qi, Saiyu QiEuroSys 2020 · 21 citations
- SecTEE: A Software-based Approach to Secure Enclave Architecture Using TEEShijun Zhao, Qianying Zhang, Yu Qin, Wei Feng et al.CCS 2019 · 95 citations
