USENIX Security2026Top-tier venue
Memclave: Secure In-Memory Enclave for Untrusted Hosts
Amit Choudhari, Fabian van Rissenbeck, Christian Rossow
Abstract
Cloud platforms run data-intensive workloads in multi-tenant settings, where frequent CPU-memory traffic can leak access patterns via cache side channels. Processing-in-Memory (PIM) devices such as UPMEM move computation into DRAM, sharply reducing data movement and shrinking the CPU cache footprint. However, commercial PIM architectures expose a host-programmed control plane and host-shared module memory, leaving device-resident code and data vulnerable to a compromised host. Existing secure-PIM proposals either add encryption/access-control hardware or rely on heavyweight host-side cryptographic protocols, complicating practical deployment. We present Memclave, a software-only framework that brings code integrity and data confidentiality to commodity PIM without hardware changes. A TPM-attested hypervisor permanently isolates the PIM's control plane from host access at boot. On each in-memory core, a trusted loader authenticates the user kernel and establishes a per-session protected data path. Memclave preserves the programming model and kernel code: host applications replace a small set of data-movement calls with secure drop-ins, keeping the trusted computing base small and porting effort low. We implement Memclave on off-the-shelf UPMEM DIMMs and evaluate it across the PrIM benchmark suite, covering heterogeneous memory-access, compute, and synchronization patterns. After a one-time ∼100 ms authenticated load, in-memory kernel time remains close to the PIM baseline: Multilayer Perceptron (MLP) stays within 1.5× at practical sizes, and Breadth-First Search (BFS) is 1.1× on some graphs with modest rise as number of frontier levels increase.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on14
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- SIMDRAM: a framework for bit-serial SIMD processing using DRAMNastaran Hajinazar, Geraldo F. Oliveira, Sven Gregorio, João Dinis Ferreira et al.ASPLOS 2021 · 182 citations
- Enabling Rack-scale Confidential Computing using Heterogeneous Trusted Execution EnvironmentJianping Zhu, Rui Hou, XiaoFeng Wang, Wenhao Wang et al.S&P 2020 · 95 citations
- SPRIGHT: extracting the server from serverless computing! high-performance eBPF-based event-driven, shared-memory processingShixiong Qi, Leslie Monis, Ziteng Zeng, Ian-Chin Wang et al.SIGCOMM 2022 · 85 citations
- Pathfinding Future PIM Architectures by Demystifying a Commercial PIM TechnologyBongjoon Hyun, Taehun Kim, Dongjae Lee, Minsoo RhuHPCA 2024 · 62 citations
Related papers
- Enabling Low-Cost Secure Computing on Untrusted In-Memory ArchitecturesSahar Ghoflsaz Ghinani, Jingyao Zhang, Elaheh SadrediniUSENIX Security 2025
- Accelerating Transactional Execution via Processing-In-MemoryAndré Lopes, Daniel Castro, Paolo RomanoEuroSys 2026
- SecTEE: A Software-based Approach to Secure Enclave Architecture Using TEEShijun Zhao, Qianying Zhang, Yu Qin, Wei Feng et al.CCS 2019 · 95 citations
- PIM-STM: Software Transactional Memory for Processing-In-Memory SystemsAndré Lopes, Daniel Castro, Paolo RomanoASPLOS 2024 · 12 citations
- xMP: Selective Memory Protection for Kernel and User SpaceSergej Proskurin, Marius Momeu, Seyedhamed Ghavamnia, Vasileios P. Kemerlis et al.S&P 2020 · 89 citations
