Counter-light Memory Encryption
Xin Wang, Jagadish Kotra, Alex Jones, Wenjie Xiong, Xun Jian
摘要
Unlike the well-known counter mode memory encryption (e.g., SGX1), more recent memory encryption (e.g., SGX2, SEV) has no counters. Without accessing any counters, such counterless memory encryption improves performance over counter mode encryption and gains wide adoption as a result.
Counterless encryption, however, still incurs a costly performance overhead. Under counterless encryption, the cipher calculations take data as their direct inputs. As such, the ciphers for decrypting data can only be calculated sequentially after the missing data arrive from memory; this requires every last-level cache miss to stall on the cipher calculations after the needed data arrive from memory. Our real-system measurements find counterless encryption can slow down irregular workloads by 9%, on average.
We observe while counter mode encryption incurs costly memory access overhead, its cipher calculations can often complete before data arrive because they take counters as input, instead of data, and counters can fit on-chip much better than data. As such, we explore how to combine both modes of encryption to achieve the best of both worlds -the efficient memory accesses of counterless encryption and fast cipher calculations of counter mode encryption. For irregular workloads, our proposed memory encryption -Counter-light Encryption -achieves 98% the average performance of no memory encryption. When memory bandwidth is starved, Counter-light Encryption is slower than counterless encryption by only 1.4% in the worst case. LLC Read Miss LLC Writeback Protects Against Memory Overhead Counterless No overhead accesses; Always calculate cipher after data arrives. No overhead accesses. Physical (or software) probing and nonreplay-based tampering. No memory overhead. Counter-light (Our work) No overhead accesses; Calculate cipher after data arrives only if counter misses in AES memoization table. Overhead accesses only in epochs with spare bandwidth. Same as counterless; also faces the same consequences under replay attacks. Same as counter mode. Counter mode Always access counters; Calculate cipher after data arrives only if counter misses in AES memoization table. Always access counters. Physical (or software) probing and all tampering including replay. 1.6% of memory, assuming split counters design.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Efficient Security Support for CXL Memory through Adaptive Incremental Offloaded (Re-)EncryptionChuanhan Li, Jishen Zhao, Yuanchao XuMICRO 2025 · 被引用 5 次
- Assassyn: A Unified Abstraction for Architectural Simulation and ImplementationJian Weng, Boyang Han, Derui Gao, Ruijie Gao 等ISCA 2025 · 被引用 1 次
- COSMOS: RL-Enhanced Locality-Aware Counter Cache Optimization for Secure MemoryHaoran Geng, Xiaoyang Lu, Yuezhi Che, Ziang Tian 等MICRO 2025 · 被引用 1 次
它引用的顶会 Paper10
- CIPHERLEAKS: Breaking Constant-time Cryptography on AMD SEV via the Ciphertext Side ChannelMengyuan Li, Yinqian Zhang, Huibo Wang, Kang Li 等USENIX Security 2021 · 被引用 130 次
- SafeGuard: Reducing the Security Risk from Row-Hammer via Low-Cost Integrity ProtectionAli Fakhrzadehgan, Yale N. Patt, Prashant J. Nair, Moinuddin K. QureshiHPCA 2022 · 被引用 51 次
- Every walk's a hit: making page walks single-access cache hitsChang Hyun Park, Ilias Vougioukas, Andreas Sandberg, David Black-SchafferASPLOS 2022 · 被引用 34 次
- Common Counters: Compressed Encryption Counters for Secure GPU MemorySeonjin Na, Sunho Lee, Yeonjae Kim, Jongse Park 等HPCA 2021 · 被引用 34 次
- Compact Leakage-Free Support for Integrity and ReliabilityMeysam Taassori, Rajeev Balasubramonian, Siddhartha Chhabra, Alaa R. Alameldeen 等ISCA 2020 · 被引用 22 次
相关 Paper
- Self-Reinforcing Memoization for Cryptography Calculations in Secure Memory SystemsXin Wang, Daulet Talapkaliyev, Matthew Hicks, Xun JianMICRO 2022 · 被引用 9 次
- Eager Memory Cryptography in CachesXin Wang, Jagadish B. Kotra, Xun JianMICRO 2022 · 被引用 6 次
- A Systematic Look at Ciphertext Side Channels on AMD SEV-SNPMengyuan Li, Luca Wilke, Jan Wichelmann, Thomas Eisenbarth 等S&P 2022 · 被引用 87 次
- MC-ORAM: A Mask-Assisted and Counter-Based Non-Deterministic ORAM Inside VM-Based TEEsYongqin Wang, Rachit Rajat, Jonghyun Lee, Mengyuan Li 等ISCA 2026
- Crystalor: Recoverable Memory Encryption Mechanism with Optimized Metadata StructureRei Ueno, Hiromichi Haneda, Naofumi Homma, Akiko Inoue 等CCS 2024
