상세 보기
KVSEV: A Secure In-Memory Key-Value Store with Secure Encrypted Virtualization
- You, Junseung;
- Lee, Kyeongryong;
- Moon, Hyungon;
- Cho, Yeongpil;
- Paek, Yunheung
WEB OF SCIENCE
2SCOPUS
3초록
AMD’s Secure Encrypted Virtualization (SEV) is a hardware-based Trusted Execution Environment (TEE) designed to secure tenants’ data on the cloud, even against insider threats. The latest version of SEV, SEV-Secure Nested Paging (SEV-SNP), offers protection against most well-known attacks such as cold boot and hypervisor-based attacks. However, it remains susceptible to a specific type of attack known as Active DRAM Corruption (ADC), where attackers manipulate memory content using specially crafted memory devices. The in-memory key-value store (KVS) on SEV is a prime target for ADC attacks due to its critical role in cloud infrastructure and the predictability of its data structures. To counter this threat, we propose KVSEV, an in-memory KVS resilient to ADC attacks. KVSEV leverages SNP’s Virtual Machine Management (VMM) and attestation mechanism to protect the integrity of key-value pairs, thereby securing the KVS from ADC attacks. Our evaluation shows that KVSEV secures in-memory KVSs on SEV with a performance overhead comparable to other secure in-memory KVS solutions. © 2023 Copyright held by the owner/author(s). Publication rights licensed to ACM.
키워드
- 제목
- KVSEV: A Secure In-Memory Key-Value Store with Secure Encrypted Virtualization
- 저자
- You, Junseung; Lee, Kyeongryong; Moon, Hyungon; Cho, Yeongpil; Paek, Yunheung
- 발행일
- 2023-10
- 유형
- Proceedings Paper
- 저널명
- PROCEEDINGS OF THE 2023 ACM SYMPOSIUM ON CLOUD COMPUTING, SOCC 2023
- 페이지
- 233 ~ 248