sRDMA - Efficient NIC-based Authentication and Encryption for Remote Direct Memory Access
Konstantin Taranov, Benjamin Rothenberger, Adrian Perrig, Torsten Hoefler
Abstract
State-of-the-art remote direct memory access (RDMA) technologies have shown to be vulnerable against attacks by innetwork adversaries, as they provide only a weak form of protection by including access tokens in each message. A network eavesdropper can easily obtain sensitive information and modify bypassing packets, affecting not only secrecy but also integrity. Tampering with packets can have drastic consequences. For example, when memory pages with code are changed remotely, altering packet contents enables remote code injection. We propose sRDMA, a protocol that provides efficient authentication and encryption for RDMA to prevent information leakage and message tampering. sRDMA uses symmetric cryptography and employs network interface cards to perform cryptographic operations. Additionally, we provide an implementation for sRDMA using programmable network adapters.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c1df2d75-dbe7-423c-b7f5-f79e63ae4c75Cited by top-tier papers18
- Clio: a hardware-software co-designed disaggregated memory systemZhiyuan Guo, Yizhou Shan, Xuhao Luo, Yutong Huang et al.ASPLOS 2022 · 110 citations
- No Provisioned Concurrency: Fast RDMA-codesigned Remote Fork for Serverless ComputingXingda Wei, Fangming Lu, Tianxia Wang, Jinyu Gu et al.OSDI 2023 · 78 citations
- ReDMArk: Bypassing RDMA Security MechanismsBenjamin Rothenberger, Konstantin Taranov, Adrian Perrig, Torsten HoeflerUSENIX Security 2021 · 56 citations
- Naos: Serialization-free RDMA networking in JavaKonstantin Taranov, Rodrigo Bruno, Gustavo Alonso, Torsten HoeflerUSENIX ATC 2021 · 31 citations
- MigrOS: Transparent Live-Migration Support for Containerised RDMA ApplicationsMaksym Planeta, Jan Bierbaum, Leo Sahaya Daphne Antony, Torsten Hoefler et al.USENIX ATC 2021 · 27 citations
Builds on2
Related papers
- Bedrock: Programmable Network Support for Secure RDMA SystemsJiarong Xing, Kuo-Feng Hsu, Yiming Qiu, Ziyang Yang et al.USENIX Security 2022
- Semantics of Remote Direct Memory Access: Operational and Declarative Models of RDMA on TSO ArchitecturesGuillaume Ambal, Brijesh Dongol, Haggai Eran, Vasileios Klimis et al.OOPSLA 2024 · 11 citations
- 1RMA: Re-envisioning Remote Memory Access for Multi-tenant DatacentersArjun Singhvi, Aditya Akella, Dan Gibson, Thomas F. Wenisch et al.SIGCOMM 2020 · 70 citations
- NeVerMore: Exploiting RDMA Mistakes in NVMe-oF Storage ApplicationsKonstantin Taranov, Benjamin Rothenberger, Daniele De Sensi, Adrian Perrig et al.CCS 2022 · 8 citations
- Accelerating Secure Collaborative Machine Learning with Protocol-Aware RDMAZhenghang Ren, Mingxuan Fan, Zilong Wang, Junxue Zhang et al.USENIX Security 2024 · 6 citations
