D-Shield: Enabling Processor-side Encryption and Integrity Verification for Secure NVMe Drives
Md Hafizul Islam Chowdhuryy, Myoungsoo Jung, Fan Yao, Amro Awad
摘要
Ensuring the confidentiality and integrity of data stored in storage disks is essential to protect users’ sensitive and private data. Recent developments of hardware-based attacks have motivated the need to secure storage data not only at rest but also in transit. Unfortunately, existing techniques such as software-based disk encryption and hardware-based self-encrypting disks fail to offer such comprehensive protection in today’s adversarial settings. With the advances of NVMe SSDs promising ultralow I/O latencies and high parallelism, architecting a storage subsystem that ensures the security of data storage in fast disks without adversely sacrificing their performance is critical.In this paper, we present D-Shield, a processor-side secure framework to holistically protect NVMe storage data confidentiality and integrity with low overheads. D-Shield integrates a novel DMA Interception Engine that allows the processor to perform security metadata maintenance and data protection without any modification to the NVMe protocol and NVMe disks. We further propose optimized D-Shield schemes that minimize decryption/re-encryption overheads for data transfer crossing security domains and utilize efficient in-memory caching of storage metadata to further boost system performance. We implement D-Shield prototypes and evaluate their efficacy using a set of synthetic and real-world benchmarks. Our results show that D-Shield can introduce up to 17× speedup for I/O intensive workloads compared to software-based protection schemes. For server-class database and graph applications, D-Shield achieves up to 96% higher throughput over software-based encryption and integrity checking mechanisms, while providing strong security guarantee against off-chip storage attacks. Meanwhile, D-Shield shows only 6% overhead on effective performance on real-world workloads and has modest in-storage metadata overhead and on-chip hardware cost.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper1
问问它们各自怎么用它相关 Paper
- NVMePass: A Lightweight, High-performance and Scalable NVMe Virtualization Architecture with I/O Queues PassthroughYiquan Chen, Zhen Jin, Yijing Wang, Yi Chen 等HPCA 2025 · 被引用 1 次
- SHIELD: Encrypting Persistent Data of LSM-KVS from Monolithic to Disaggregated StorageViraj Thakkar, Dongha Kim, Yingchun Lai, Hokeun Kim 等SIGMOD 2025 · 被引用 5 次
- SeDA: Secure and Efficient DNN Accelerators with Hardware/Software SynergyWei Xuan, Zhongrui Wang, Lang Feng, Ning Lin 等DAC 2025 · 被引用 3 次
- MGX: near-zero overhead memory protection for data-intensive acceleratorsWeizhe Hua, Muhammad Umar, Zhiru Zhang, G. Edward SuhISCA 2022 · 被引用 27 次
- Simurgh: a fully decentralized and secure NVMM user space file systemNafiseh Moti, Frederic Schimmelpfennig, Reza Salkhordeh, David Klopp 等SC 2021 · 被引用 11 次
