D-Shield: Enabling Processor-side Encryption and Integrity Verification for Secure NVMe Drives
Md Hafizul Islam Chowdhuryy, Myoungsoo Jung, Fan Yao, Amro Awad
Abstract
Ensuring the confidentiality and integrity of data stored in storage disks is essential to protect users’ sensitive and private data. Recent developments of hardware-based attacks have motivated the need to secure storage data not only at rest but also in transit. Unfortunately, existing techniques such as software-based disk encryption and hardware-based self-encrypting disks fail to offer such comprehensive protection in today’s adversarial settings. With the advances of NVMe SSDs promising ultralow I/O latencies and high parallelism, architecting a storage subsystem that ensures the security of data storage in fast disks without adversely sacrificing their performance is critical.In this paper, we present D-Shield, a processor-side secure framework to holistically protect NVMe storage data confidentiality and integrity with low overheads. D-Shield integrates a novel DMA Interception Engine that allows the processor to perform security metadata maintenance and data protection without any modification to the NVMe protocol and NVMe disks. We further propose optimized D-Shield schemes that minimize decryption/re-encryption overheads for data transfer crossing security domains and utilize efficient in-memory caching of storage metadata to further boost system performance. We implement D-Shield prototypes and evaluate their efficacy using a set of synthetic and real-world benchmarks. Our results show that D-Shield can introduce up to 17× speedup for I/O intensive workloads compared to software-based protection schemes. For server-class database and graph applications, D-Shield achieves up to 96% higher throughput over software-based encryption and integrity checking mechanisms, while providing strong security guarantee against off-chip storage attacks. Meanwhile, D-Shield shows only 6% overhead on effective performance on real-world workloads and has modest in-storage metadata overhead and on-chip hardware cost.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 312bf0b3-d370-4f35-bdf9-19aa92704b32Cited by top-tier papers1
Ask how each one uses itRelated papers
- NVMePass: A Lightweight, High-performance and Scalable NVMe Virtualization Architecture with I/O Queues PassthroughYiquan Chen, Zhen Jin, Yijing Wang, Yi Chen et al.HPCA 2025 · 1 citation
- SHIELD: Encrypting Persistent Data of LSM-KVS from Monolithic to Disaggregated StorageViraj Thakkar, Dongha Kim, Yingchun Lai, Hokeun Kim et al.SIGMOD 2025 · 5 citations
- SeDA: Secure and Efficient DNN Accelerators with Hardware/Software SynergyWei Xuan, Zhongrui Wang, Lang Feng, Ning Lin et al.DAC 2025 · 3 citations
- MGX: near-zero overhead memory protection for data-intensive acceleratorsWeizhe Hua, Muhammad Umar, Zhiru Zhang, G. Edward SuhISCA 2022 · 27 citations
- Simurgh: a fully decentralized and secure NVMM user space file systemNafiseh Moti, Frederic Schimmelpfennig, Reza Salkhordeh, David Klopp et al.SC 2021 · 11 citations
