Adaptive CHERI Compartmentalization for Heterogeneous Accelerators
Jianyi Cheng, A. Theodore Markettos, Alexandre Joannou, Paul Metzger, Matthew Naylor, Peter Rugg, Timothy M. Jones
摘要
Hardware accelerators offer high performance and energy efficiency for specific tasks compared to general-purpose processors. However, current hardware accelerator designs focus primarily on performance, overlooking security. This poses significant security risks due to potential memory safety violations that can affect the entire hardware system. Existing methods either rely on Input-Output Memory Management Units (IOMMUs) for memory isolation between memory pages, leading to vulnerabilities in intra-page memory accesses, or modify an accelerator architecture for specialized memory protection, which requires significant effort and cannot scale across multiple diverse applications.
In this paper, we propose a general method for fine-grained memory protection in heterogeneous systems without modifying accelerator architectures. We extend the Capability Hardware Enhanced RISC Instructions (CHERI) from CPUs to an adaptive hardware interface named CapChecker. The CapChecker imports capabilities from the CPU and guards memory accesses at the pointer level from CHERI-unaware accelerators as if they were CHERI-aware natively. Over a set of benchmarks on hardware accelerators in a heterogeneous system, our approach achieves fine-grained memory protection, with a 1.4% performance overhead compared to CHERI-unaware accelerators on average.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper9
- Thunderclap: Exploring Vulnerabilities in Operating System IOMMU Protection via DMA from Untrustworthy PeripheralsA. Theodore Markettos, Colin Rothwell, Brett F. Gutstein, Allison Pearce 等NDSS 2019 · 被引用 97 次
- A Comprehensive Analysis of Superpage Management Mechanisms and PoliciesWeixi Zhu, Alan L. Cox, Scott RixnerUSENIX ATC 2020 · 被引用 40 次
- TNPU: Supporting Trusted Execution with Tree-less Integrity Protection for Neural Processing UnitSunho Lee, Jungwoo Kim, Seonjin Na, Jongse Park 等HPCA 2022 · 被引用 37 次
- VR-DANN: Real-Time Video Recognition via Decoder-Assisted Neural Network AccelerationZhuoran Song, Feiyang Wu, Xueyuan Liu, Jing Ke 等MICRO 2020 · 被引用 29 次
- MGX: near-zero overhead memory protection for data-intensive acceleratorsWeizhe Hua, Muhammad Umar, Zhiru Zhang, G. Edward SuhISCA 2022 · 被引用 27 次
相关 Paper
- Rigorous engineering for hardware security: Formal modelling and proof in the CHERI design and implementation processKyndylan Nienhuis, Alexandre Joannou, Thomas Bauereiss, Anthony C. J. Fox 等S&P 2020 · 被引用 43 次
- Capstone: A Capability-based Foundation for Trustless Secure Memory AccessJason Zhijingcheng Yu, Conrad Watt, Aditya Badole, Trevor E. Carlson 等USENIX Security 2023
- Adaptive Security Support for Heterogeneous Memory on GPUsShougang Yuan, Amro Awad, Ardhi Wiratama Baskara Yudha, Yan Solihin 等HPCA 2022 · 被引用 15 次
- CHERIoT: Complete Memory Safety for Embedded DevicesSaar Amar, David Chisnall, Tony Chen, Nathaniel Wesley Filardo 等MICRO 2023 · 被引用 22 次
- Let-Me-In: (Still) Employing In-pointer Bounds Metadata for Fine-grained GPU Memory SafetyJaewon Lee, Euijun Chung, Saurabh Singh, Seonjin Na 等HPCA 2025 · 被引用 3 次
