KVSEV: A Secure In-Memory Key-Value Store with Secure Encrypted Virtualization

  • You, Junseung
  • Lee, Kyeongryong
  • Moon, Hyungon
  • Cho, Yeongpil
  • Paek, Yunheung
Citations

WEB OF SCIENCE

2
Citations

SCOPUS

3

초록

AMD’s Secure Encrypted Virtualization (SEV) is a hardware-based Trusted Execution Environment (TEE) designed to secure tenants’ data on the cloud, even against insider threats. The latest version of SEV, SEV-Secure Nested Paging (SEV-SNP), offers protection against most well-known attacks such as cold boot and hypervisor-based attacks. However, it remains susceptible to a specific type of attack known as Active DRAM Corruption (ADC), where attackers manipulate memory content using specially crafted memory devices. The in-memory key-value store (KVS) on SEV is a prime target for ADC attacks due to its critical role in cloud infrastructure and the predictability of its data structures. To counter this threat, we propose KVSEV, an in-memory KVS resilient to ADC attacks. KVSEV leverages SNP’s Virtual Machine Management (VMM) and attestation mechanism to protect the integrity of key-value pairs, thereby securing the KVS from ADC attacks. Our evaluation shows that KVSEV secures in-memory KVSs on SEV with a performance overhead comparable to other secure in-memory KVS solutions. © 2023 Copyright held by the owner/author(s). Publication rights licensed to ACM.

키워드

Confidential computingKey-value storeSecure Encrypted VirtualizationTrusted execution environmentsCryptographyDynamic random access storageTrusted computingVirtual reality
제목
KVSEV: A Secure In-Memory Key-Value Store with Secure Encrypted Virtualization
저자
You, JunseungLee, KyeongryongMoon, HyungonCho, YeongpilPaek, Yunheung
DOI
10.1145/3620678.3624658
발행일
2023-10
유형
Proceedings Paper
저널명
PROCEEDINGS OF THE 2023 ACM SYMPOSIUM ON CLOUD COMPUTING, SOCC 2023
페이지
233 ~ 248