Counter-light Memory Encryption
Xin Wang, Jagadish Kotra, Alex Jones, Wenjie Xiong, Xun Jian
Abstract
Unlike the well-known counter mode memory encryption (e.g., SGX1), more recent memory encryption (e.g., SGX2, SEV) has no counters. Without accessing any counters, such counterless memory encryption improves performance over counter mode encryption and gains wide adoption as a result.
Counterless encryption, however, still incurs a costly performance overhead. Under counterless encryption, the cipher calculations take data as their direct inputs. As such, the ciphers for decrypting data can only be calculated sequentially after the missing data arrive from memory; this requires every last-level cache miss to stall on the cipher calculations after the needed data arrive from memory. Our real-system measurements find counterless encryption can slow down irregular workloads by 9%, on average.
We observe while counter mode encryption incurs costly memory access overhead, its cipher calculations can often complete before data arrive because they take counters as input, instead of data, and counters can fit on-chip much better than data. As such, we explore how to combine both modes of encryption to achieve the best of both worlds -the efficient memory accesses of counterless encryption and fast cipher calculations of counter mode encryption. For irregular workloads, our proposed memory encryption -Counter-light Encryption -achieves 98% the average performance of no memory encryption. When memory bandwidth is starved, Counter-light Encryption is slower than counterless encryption by only 1.4% in the worst case. LLC Read Miss LLC Writeback Protects Against Memory Overhead Counterless No overhead accesses; Always calculate cipher after data arrives. No overhead accesses. Physical (or software) probing and nonreplay-based tampering. No memory overhead. Counter-light (Our work) No overhead accesses; Calculate cipher after data arrives only if counter misses in AES memoization table. Overhead accesses only in epochs with spare bandwidth. Same as counterless; also faces the same consequences under replay attacks. Same as counter mode. Counter mode Always access counters; Calculate cipher after data arrives only if counter misses in AES memoization table. Always access counters. Physical (or software) probing and all tampering including replay. 1.6% of memory, assuming split counters design.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext adec4949-8b8d-422e-8e13-db2697cb4a19Cited by top-tier papers3
- Efficient Security Support for CXL Memory through Adaptive Incremental Offloaded (Re-)EncryptionChuanhan Li, Jishen Zhao, Yuanchao XuMICRO 2025 · 5 citations
- Assassyn: A Unified Abstraction for Architectural Simulation and ImplementationJian Weng, Boyang Han, Derui Gao, Ruijie Gao et al.ISCA 2025 · 1 citation
- COSMOS: RL-Enhanced Locality-Aware Counter Cache Optimization for Secure MemoryHaoran Geng, Xiaoyang Lu, Yuezhi Che, Ziang Tian et al.MICRO 2025 · 1 citation
Builds on10
- CIPHERLEAKS: Breaking Constant-time Cryptography on AMD SEV via the Ciphertext Side ChannelMengyuan Li, Yinqian Zhang, Huibo Wang, Kang Li et al.USENIX Security 2021 · 130 citations
- SafeGuard: Reducing the Security Risk from Row-Hammer via Low-Cost Integrity ProtectionAli Fakhrzadehgan, Yale N. Patt, Prashant J. Nair, Moinuddin K. QureshiHPCA 2022 · 51 citations
- Every walk's a hit: making page walks single-access cache hitsChang Hyun Park, Ilias Vougioukas, Andreas Sandberg, David Black-SchafferASPLOS 2022 · 34 citations
- Common Counters: Compressed Encryption Counters for Secure GPU MemorySeonjin Na, Sunho Lee, Yeonjae Kim, Jongse Park et al.HPCA 2021 · 34 citations
- Compact Leakage-Free Support for Integrity and ReliabilityMeysam Taassori, Rajeev Balasubramonian, Siddhartha Chhabra, Alaa R. Alameldeen et al.ISCA 2020 · 22 citations
Related papers
- Self-Reinforcing Memoization for Cryptography Calculations in Secure Memory SystemsXin Wang, Daulet Talapkaliyev, Matthew Hicks, Xun JianMICRO 2022 · 9 citations
- Eager Memory Cryptography in CachesXin Wang, Jagadish B. Kotra, Xun JianMICRO 2022 · 6 citations
- A Systematic Look at Ciphertext Side Channels on AMD SEV-SNPMengyuan Li, Luca Wilke, Jan Wichelmann, Thomas Eisenbarth et al.S&P 2022 · 87 citations
- MC-ORAM: A Mask-Assisted and Counter-Based Non-Deterministic ORAM Inside VM-Based TEEsYongqin Wang, Rachit Rajat, Jonghyun Lee, Mengyuan Li et al.ISCA 2026
- Crystalor: Recoverable Memory Encryption Mechanism with Optimized Metadata StructureRei Ueno, Hiromichi Haneda, Naofumi Homma, Akiko Inoue et al.CCS 2024
