ShEF: shielded enclaves for cloud FPGAs
Mark Zhao, Mingyu Gao, Christos Kozyrakis
Abstract
FPGAs are now used in public clouds to accelerate a wide range of applications, including many that operate on sensitive data such as financial and medical records. We present ShEF, a trusted execution environment (TEE) for cloud-based reconfigurable accelerators. ShEF is independent from CPU-based TEEs and allows secure execution under a threat model where the adversary can control all software running on the CPU connected to the FPGA, has physical access to the FPGA, and can compromise the FPGA interface logic of the cloud provider. ShEF provides a secure boot and remote attestation process that relies solely on existing FPGA mechanisms for root of trust. It also includes a Shield component that provides secure access to data while the accelerator is in use. The Shield is highly customizable and extensible, allowing users to craft a bespoke security solution that fits their accelerator's memory access patterns, bandwidth, and security requirements at minimum performance and area overheads. We describe a prototype implementation of ShEF for existing cloud FPGAs, map ShEF to a performant and secure storage application, and measure the performance benefits of customizable security using five additional accelerators.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a39a6f59-72bd-429a-8be0-ea01631e2d6cCited by top-tier papers11
- ACAI: Protecting Accelerator Execution with Arm Confidential Computing ArchitectureSupraja Sridhara, Andrin Bertschi, Benedict Schlüter, Mark Kuhne et al.USENIX Security 2024 · 36 citations
- Confidential Computing within an AI AcceleratorKapil Vaswani, Stavros Volos, Cédric Fournet, Antonio Nino Diaz et al.USENIX ATC 2023 · 31 citations
- GuardNN: secure accelerator architecture for privacy-preserving deep learningWeizhe Hua, Muhammad Umar, Zhiru Zhang, G. Edward SuhDAC 2022 · 28 citations
- sNPU: Trusted Execution Environments on Integrated NPUsErhu Feng, Dahu Feng, Dong Du, Yubin Xia et al.ISCA 2024 · 13 citations
- TNIC: A Trusted NIC Architecture: A hardware-network substrate for building high-performance trustworthy distributed systemsDimitra Giantsidi, Julian Pritzi, Felix Gust, Antonios Katsarakis et al.ASPLOS 2025 · 4 citations
Builds on18
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
Related papers
- AccShield: a New Trusted Execution Environment with Machine-Learning AcceleratorsWei Ren, William Kozlowski, Sandhya Koteshwara, Mengmei Ye et al.DAC 2023 · 11 citations
- SGX-FPGA: Trusted Execution Environment for CPU-FPGA Heterogeneous ArchitectureKe Xia, Yukui Luo, Xiaolin Xu, Sheng WeiDAC 2021 · 39 citations
- SoK: Analysis of Accelerator TEE DesignsChenxu Wang, Junjie Huang, Yujun Liang, Xuanyao Peng et al.NDSS 2026 · 2 citations
- FPGA-TrustZone: Security Extension of TrustZone to FPGA for SoC-FPGA Heterogeneous ArchitectureShupeng Wang, Xindong Fan, Xiao Xu, Shuchen Wang et al.DAC 2025 · 1 citation
- Salus: A Practical Trusted Execution Environment for CPU-FPGA Heterogeneous Cloud PlatformsYu Zou, Yiran Li, Sheng Wang, Le Su et al.ASPLOS 2024 · 3 citations
