SmartNIC Security Isolation in the Cloud with S-NIC
Yang Zhou, Mark Wilkening, James Mickens, Minlan Yu
Abstract
Modern smart NICs provide little isolation between the network functions belonging to different tenants. These NICs also do not protect network functions from the datacenter-provided management OS which runs on the smart NIC. We describe concrete attacks which allow a network function's state to leak to (or be modified by) another network function or the management OS. We then introduce S-NIC, a new hardware design for smart NICs that provides strong isolation guarantees. S-NIC pervasively virtualizes hardware accelerators, enforces single-owner semantics for each line in on-NIC cache and RAM, and provides dedicated bus bandwidth for each network function. Using this design, we eliminate side channels involving shared hardware state, and give each network function the illusion of having a private smart NIC. We show how these virtual NICs can be integrated with preexisting datacenter technologies for virtual LANs and trusted host-level computations like SGX enclaves. The overall result is that S-NIC enables strongly-isolated, NIC-accelerated datacenter applications; in these applications, network functions and host-level code receive hardware-guaranteed isolation from other applications and the datacenter provider.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext edda68ad-bb39-4caa-9b78-5082f9b30b48Cited by top-tier papers2
- Toleo: Scaling Freshness to Tera-scale Memory Using CXL and PIMJuechu Dong, Jonah Rosenblum, Satish NarayanasamyASPLOS 2024 · 8 citations
- Nezha: SmartNIC-based Virtual Switch Load SharingXing Li, Enge Song, Bowen Yang, Tian Pan et al.SIGCOMM 2025 · 3 citations
Builds on12
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice et al.USENIX Security 2016 · 451 citations
- T-SGX: Eradicating Controlled-Channel Attacks Against Enclave ProgramsMing-Wei Shih, Sangho Lee, Taesoo Kim, Marcus PeinadoNDSS 2017 · 431 citations
- Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB AttacksBen Gras, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaUSENIX Security 2018 · 357 citations
Related papers
- SmartNIC Performance Isolation with FairNICStewart Grant, Anil Yelam, Maxwell Bland, Alex C. SnoerenSIGCOMM 2020 · 62 citations
- Composable Cachelets: Protecting Enclaves from Cache Side-Channel AttacksDaniel Townley, Kerem Arikan, Yu David Liu, Dmitry Ponomarev et al.USENIX Security 2022
- OSMOSIS: Enabling Multi-Tenancy in Datacenter SmartNICsMikhail Khalilov, Marcin Chrapek, Siyuan Shen, Alessandro Vezzu et al.USENIX ATC 2024 · 14 citations
- TNIC: A Trusted NIC Architecture: A hardware-network substrate for building high-performance trustworthy distributed systemsDimitra Giantsidi, Julian Pritzi, Felix Gust, Antonios Katsarakis et al.ASPLOS 2025 · 4 citations
- AEX-Notify: Thwarting Precise Single-Stepping Attacks through Interrupt Awareness for Intel SGX EnclavesScott Constable, Jo Van Bulck, Xiang Cheng, Yuan Xiao et al.USENIX Security 2023
