首页> 外文会议>International Symposium on High-Performance Computer Architecture >SENSS: security enhancement to symmetric shared memory multiprocessors
【24h】

SENSS: security enhancement to symmetric shared memory multiprocessors

机译:SENS:对对称共享内存多处理器的安全性增强

获取原文
获取外文期刊封面目录资料

摘要

With the increasing concern of the security on high performance multiprocessor enterprise servers, more and more effort is being invested into defending against various kinds of attacks. This paper proposes a security enhancement model called SENSS, that allows programs to run securely on a symmetric shared memory multiprocessor (SMP) environment. In SENSS, a program, including both code and data, is stored in the shared memory in encrypted form but is decrypted once it is fetched into any of the processors. In contrast to the traditional uniprocessor XOM model (Lie et al., 2000), the main challenge in developing SENSS lies in the necessity for guarding the clear text communication between processors in a multiprocessor environment. In this paper we propose an inexpensive solution that can effectively protect the shared bus communication. The proposed schemes include both encryption and authentication for bus transactions. We develop a scheme that utilizes the cipher block chaining mode of the advanced encryption standard (CBC-AES) to achieve ultra low latency for the shared bus encryption and decryption. In addition, CBC-AES can generate integrity checking code for the bus communication over time, achieving bus authentication. Further, we develop techniques to ensure the cryptographic computation throughput meets the high bandwidth of gigabyte buses. We performed full system simulation using Simics to measure the overhead of the security features on a SMP system with a snooping write invalidate cache coherence protocol. Overall, only a slight performance degradation of 2.03% on average was observed when the security is provided at the highest level.
机译:随着高性能多处理器企业服务器的安全越来越多,越来越多的努力正在捍卫各种攻击。本文提出了一种称为SENS的安全增强型,允许程序安全地运行对称的共享内存多处理器(SMP)环境。在SENS中,包括代码和数据的程序,包括加密形式的共享内存中,但是一旦被获取到任何处理器中,就会被解密。与传统的Uniprocessor XOM型号相比(Lie等人,2000),开发SENS中的主要挑战在于保护多处理器环境中处理器之间的清晰文本通信的必要性。在本文中,我们提出了一种廉价的解决方案,可以有效地保护共享总线通信。建议的方案包括总线事务的加密和认证。我们开发了一种利用高级加密标准(CBC-AES)的密码块链式模式的方案,以实现共享总线加密和解密的超低延迟。此外,CBC-AES可以随时间生成总线通信的完整性检查代码,实现总线认证。此外,我们开发技术以确保加密计算吞吐量符合千兆字节总线的高带宽。我们使用SIMICS进行了完整的系统模拟,以测量SMP系统上的安全功能的开销,并具有侦听写入无效缓存相干协调协议。总的来说,当在最高水平提供安全性时,只有平均的平均性能降低2.03%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号