IceClave: A Trusted Execution Environment for In-Storage Computing
Luyi Kang, Yuqi Xue, Weiwei Jia, Xiaohao Wang, Jongryool Kim, Changhwan Youn, Myeong Joon Kang, Hyung Jin Lim, Bruce L. Jacob, Jian Huang
摘要
In-storage computing with modern solid-state drives (SSDs) enables developers to offload programs from the host to the SSD. It has been proven to be an effective approach to alleviate the I/O bottleneck. To facilitate in-storage computing, many frameworks have been proposed. However, few of them treat the in-storage security as the first citizen. Specifically, since modern SSD controllers do not have a trusted execution environment, an offloaded (malicious) program could steal, modify, and even destroy the data stored in the SSD.
In this paper, we first investigate the attacks that could be conducted by offloaded in-storage programs. To defend against these attacks, we build a lightweight trusted execution environment, named IceClave for in-storage computing. IceClave enables security isolation between in-storage programs and flash management functions that include flash address translation, data access control, and garbage collection, with TrustZone extensions. IceClave also achieves security isolation between in-storage programs by enforcing memory integrity verification of in-storage DRAM with low overhead. To protect data loaded from flash chips, IceClave develops a lightweight data encryption/decryption mechanism in flash controllers. We develop IceClave with a full system simulator. We evaluate IceClave with a variety of data-intensive applications such as databases. Compared to state-of-the-art in-storage computing approaches, IceClave introduces only 7.6% performance overhead, while enforcing security isolation in the SSD controller with minimal hardware cost. IceClave still keeps the performance benefit of in-storage computing by delivering up to 2.31× better performance than the conventional host-based trusted computing approach.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- Flash-Cosmos: In-Flash Bulk Bitwise Operations Using Inherent Computation Capability of NAND Flash MemoryJisung Park, Roknoddin Azizi, Geraldo F. Oliveira, Mohammad Sadrosadati 等MICRO 2022 · 被引用 53 次
- LeaFTL: A Learning-Based Flash Translation Layer for Solid-State DrivesJinghan Sun, Shaobo Li, Yunxin Sun, Chao Sun 等ASPLOS 2023 · 被引用 38 次
- ACAI: Protecting Accelerator Execution with Arm Confidential Computing ArchitectureSupraja Sridhara, Andrin Bertschi, Benedict Schlüter, Mark Kuhne 等USENIX Security 2024 · 被引用 36 次
- Venice: Improving Solid-State Drive Parallelism at Low Cost via Conflict-Free AccessesRakesh Nadig, Mohammad Sadrosadati, Haiyu Mao, Nika Mansouri-Ghiasi 等ISCA 2023 · 被引用 29 次
- Dissecting BFT Consensus: In Trusted Components we Trust!Suyash Gupta, Sajjad Rahnama, Shubham Pandey, Natacha Crooks 等EuroSys 2023 · 被引用 27 次
它引用的顶会 Paper8
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 被引用 649 次
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic 等EuroSys 2020 · 被引用 381 次
- EnclaveDB: A Secure Database Using SGXChristian Priebe, Kapil Vaswani, Manuel CostaS&P 2018 · 被引用 329 次
- OBLIVIATE: A Data Oblivious Filesystem for Intel SGXAdil Ahmad, Kyungtae Kim, Muhammad Ihsanulhaq Sarfaraz, Byoungyoung LeeNDSS 2018 · 被引用 144 次
相关 Paper
- DockerSSD: Containerized In-Storage Processing and Hardware Acceleration for Computational SSDsDonghyun Gouk, Miryeong Kwon, Hanyeoreum Bae, Myoungsoo JungHPCA 2024 · 被引用 7 次
- Conduit: Programmer-Transparent Near-Data Processing Using Multiple Compute-Capable Resources in Solid State DrivesRakesh Nadig, Vamanan Arulchelvan, Mayank Kabra, Harshita Gupta 等HPCA 2026 · 被引用 2 次
- SaS: SSD as SQL Database SystemJong-Hyeok Park, Soyee Choi, Gihwan Oh, Sang Won LeeVLDB 2021 · 被引用 13 次
- Building Enclave-Native Storage Engines for Practical Encrypted DatabasesYuanyuan Sun, Sheng Wang, Huorong Li, Feifei LiVLDB 2021 · 被引用 56 次
- A Hardware-Software Co-design for Efficient Intra-Enclave IsolationJinyu Gu, Bojun Zhu, Mingyu Li, Wentai Li 等USENIX Security 2022
