Root Crash Consistency of SGX-style Integrity Trees in Secure Non-Volatile Memory Systems
Jianming Huang, Yu Hua
Abstract
Data integrity is important for non-volatile memory (NVM) systems that maintain data even without power. The data integrity in NVM may be compromised by integrity attacks, which can be defended against by integrity verification via integrity trees. After NVM system failures and reboots, the integrity tree root is responsible for providing a trusted execution environment. However, updating the root incurs latency to propagate the modifications from leaf nodes to the root. If system crashes occur during the propagation process, the root is inconsistent with the updated leaf nodes, resulting in misreporting the attacks after the system reboots. In this paper, we propose a ShortCut UpdatE scheme, called SCUE, which is an efficient and low-latency scheme to instantaneously update the root on the SGX-style integrity tree (SIT) by judiciously overlooking the updates upon most intermediate tree nodes. The idea behind SCUE explores and exploits the observation that consistent leaf nodes and root are enough to ensure data integrity after system failures and reboots. Moreover, SIT is difficult to be reconstructed from the leaf nodes since updating one tree node needs its parent node as input. Root in SIT thus cannot verify the data after the system crashes and reboots even though the root is correctly updated. To provide the ability of verification via root in SIT, we use a counter-summing approach to efficiently reconstructing the SIT from leaf nodes. Extensive evaluation results show that compared with the state-of-the-art integrity tree update schemes, our SCUE delivers high performance while ensuring data integrity.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7636a407-733f-47a4-bbc7-a7e274fa9d51Builds on7
- NVAlloc: rethinking heap metadata management in persistent memory allocatorsZheng Dang, Shuibing He, Peiyi Hong, Zhenxin Li et al.ASPLOS 2022 · 35 citations
- BBB: Simplifying Persistent Programming using Battery-Backed BuffersMohammad A. Alshboul, Prakash Ramrakhyani, William Wang, James Tuck et al.HPCA 2021 · 34 citations
- Bonsai Merkle Forests: Efficiently Achieving Crash Consistency in Secure Persistent MemoryAlexander Freij, Huiyang Zhou, Yan SolihinMICRO 2021 · 32 citations
- MorLog: Morphable Hardware Logging for Atomic Persistence in Non-Volatile Main MemoryXueliang Wei, Dan Feng, Wei Tong, Jingning Liu et al.ISCA 2020 · 23 citations
- A Write-Friendly and Fast-Recovery Scheme for Security Metadata in Non-Volatile MemoriesJianming Huang, Yu HuaHPCA 2021 · 14 citations
Related papers
- ROTE: Rollback Protection for Trusted ExecutionSinisa Matetic, Mansoor Ahmed, Kari Kostiainen, Aritra Dhar et al.USENIX Security 2017 · 249 citations
- Compact Leakage-Free Support for Integrity and ReliabilityMeysam Taassori, Rajeev Balasubramonian, Siddhartha Chhabra, Alaa R. Alameldeen et al.ISCA 2020 · 22 citations
- A Midsummer Night's Tree: Efficient and High Performance Secure SCMSamuel Thomas, Kidus Workneh, Jac McCarty, Joseph Izraelevitz et al.ASPLOS 2024 · 5 citations
- Crystalor: Recoverable Memory Encryption Mechanism with Optimized Metadata StructureRei Ueno, Hiromichi Haneda, Naofumi Homma, Akiko Inoue et al.CCS 2024
- Towards Formal Verification of State Continuity for Enclave ProgramsMohit Kumar Jangid, Guoxing Chen, Yinqian Zhang, Zhiqiang LinUSENIX Security 2021 · 18 citations
