File Download
There are no files associated with this item.
Links for fulltext
(May Require Subscription)
- Publisher Website: 10.1109/MICRO56248.2022.00019
- Scopus: eid_2-s2.0-85141676489
- WOS: WOS:000886530600008
Supplementary
- Citations:
- Appears in Collections:
Conference Paper: CRONUS: Fault-isolated, Secure and High-performance Heterogeneous Computing for Trusted Execution Environment
Title | CRONUS: Fault-isolated, Secure and High-performance Heterogeneous Computing for Trusted Execution Environment |
---|---|
Authors | |
Keywords | Accelerator ARM TrustZone Fault isolation GPU Security isolation Trusted Execution Environment |
Issue Date | 5-Oct-2022 |
Abstract | With the trend of processing a large volume of sensitive data on PaaS services (e.g., DNN training), a TEE architecture that supports general heterogeneous accelerators, enables spatial sharing on one accelerator, and enforces strong isolation across accelerators is highly desirable. However, none of the existing TEE solutions meet all three requirements. In this paper, we propose CRONUS, the first TEE architecture that achieves the three crucial requirements. The key idea of CRONUS is to partition heterogeneous computation into isolated TEE enclaves, where each enclave encapsulates only one kind of computation (e.g., GPU computation), and multiple enclaves can spatially share an accelerator. Then, CRONUS constructs heterogeneous computing using remote procedure calls (RPCs) among enclaves. With CRONUS, each accelerator’s hardware and its software stack are strongly isolated from others’, and each enclave trusts only its own hardware. To tackle the security challenge caused by inter-enclave interactions, we design a new streaming remote procedure call abstraction to enable secure RPCs with high performance. CRONUS is software-based, making it general to diverse accelerators. We implemented CRONUS on ARM TrustZone. Evaluation on diverse workloads with CPUs, GPUs and NPUs shows that, CRONUS achieves less than 7.1% extra computation time compared to native (unprotected) executions. |
Persistent Identifier | http://hdl.handle.net/10722/333866 |
ISI Accession Number ID |
DC Field | Value | Language |
---|---|---|
dc.contributor.author | Jiang, Jianyu | - |
dc.contributor.author | Qi, Ji | - |
dc.contributor.author | Shen, Tianxiang | - |
dc.contributor.author | Chen, Xusheng | - |
dc.contributor.author | Zhao, Shixiong | - |
dc.contributor.author | Wang, Sen | - |
dc.contributor.author | Chen, Li | - |
dc.contributor.author | Zhang, Gong | - |
dc.contributor.author | Luo, Xiapu | - |
dc.contributor.author | Cui, Heming | - |
dc.date.accessioned | 2023-10-06T08:39:44Z | - |
dc.date.available | 2023-10-06T08:39:44Z | - |
dc.date.issued | 2022-10-05 | - |
dc.identifier.uri | http://hdl.handle.net/10722/333866 | - |
dc.description.abstract | <p>With the trend of processing a large volume of sensitive data on PaaS services (e.g., DNN training), a TEE architecture that supports general heterogeneous accelerators, enables spatial sharing on one accelerator, and enforces strong isolation across accelerators is highly desirable. However, none of the existing TEE solutions meet all three requirements. In this paper, we propose CRONUS, the first TEE architecture that achieves the three crucial requirements. The key idea of CRONUS is to partition heterogeneous computation into isolated TEE enclaves, where each enclave encapsulates only one kind of computation (e.g., GPU computation), and multiple enclaves can spatially share an accelerator. Then, CRONUS constructs heterogeneous computing using remote procedure calls (RPCs) among enclaves. With CRONUS, each accelerator’s hardware and its software stack are strongly isolated from others’, and each enclave trusts only its own hardware. To tackle the security challenge caused by inter-enclave interactions, we design a new streaming remote procedure call abstraction to enable secure RPCs with high performance. CRONUS is software-based, making it general to diverse accelerators. We implemented CRONUS on ARM TrustZone. Evaluation on diverse workloads with CPUs, GPUs and NPUs shows that, CRONUS achieves less than 7.1% extra computation time compared to native (unprotected) executions.<br></p> | - |
dc.language | eng | - |
dc.relation.ispartof | 2022 55th IEEE/ACM International Symposium on Microarchitecture (MICRO) (01/10/2022-05/10/2022, Chicago) | - |
dc.subject | Accelerator | - |
dc.subject | ARM TrustZone | - |
dc.subject | Fault isolation | - |
dc.subject | GPU | - |
dc.subject | Security isolation | - |
dc.subject | Trusted Execution Environment | - |
dc.title | CRONUS: Fault-isolated, Secure and High-performance Heterogeneous Computing for Trusted Execution Environment | - |
dc.type | Conference_Paper | - |
dc.identifier.doi | 10.1109/MICRO56248.2022.00019 | - |
dc.identifier.scopus | eid_2-s2.0-85141676489 | - |
dc.identifier.volume | 2022-October | - |
dc.identifier.spage | 124 | - |
dc.identifier.epage | 143 | - |
dc.identifier.isi | WOS:000886530600008 | - |