SxSSD:一种安全且可扩展的软件定义固态硬盘
SxSSD: A Secure and Extensible Software-defined Solid State Drive
浏览论文内容
中文总结 AI 辅助
SxSSD是一种安全可扩展的软件定义固态硬盘,通过解耦FTL策略与机制,既保留传统FTL的隔离安全性,又提升了灵活性,其原型开销远小于原生FTL实现。
中文摘要 AI 辅助
固态硬盘(SSD)基于NAND闪存构建,通过基于块的存储接口将其暴露给操作系统。由于NAND闪存受硬件特性限制存在特殊的读写约束,因此需要在操作系统级I/O与原始闪存I/O之间进行转换,这就形成了闪存转换层(FTL),该层因与操作系统物理隔离而构成了“可信计算基”。基于该可信计算基,一些安全设计(例如从恶意软件攻击中恢复数据)即使在操作系统被入侵时也能确保强大的数据安全属性。然而,这些安全设计大多需要修改FTL的固件代码,而实际上这很难实现,因为传统的基于块的FTL并未提供修改其内部功能的接口。新型闪存存储接口设计(如开放通道SSD或分区命名空间)已将FTL的关键功能移至操作系统,这些接口降低了修改FTL功能的难度,但代价是模糊了可信边界,因为FTL不再与操作系统隔离。在本研究中,我们提出了SxSSD,一种安全且可扩展的软件定义SSD设计。通过将内部策略定义与原始FTL机制解耦,我们允许可信应用程序动态且安全地定义FTL策略和暴露的存储接口(与开放通道SSD和分区命名空间SSD相比,实现了更高的灵活性)。最重要的是,SxSSD保留了传统FTL执行的隔离性(实现了与传统基于块的SSD相似的安全性)。我们已识别并解决了在操作系统被入侵情况下引入的关键安全挑战。此外,我们已实现SxSSD的原型,并针对不同的FTL策略和存储接口评估其开销。实验评估表明,与原生FTL实现相比,SxSSD产生的开销很小。
英文摘要
Solid-state drives (SSDs) are built on NAND flash memory and expose it to the operating system through a block-based storage interface. As NAND flash has special read/write constraints due to its hardware nature, a translation between OS-level I/Os and raw flash memory I/Os is needed. This results in a flash translation layer (FTL) that creates a ``trusted computing base'' due to its physical isolation from the OS. Building on this trusted computing base, some security designs (e.g., data recovery from malware attacks) can ensure strong data security properties even if the OS is compromised. However, they mostly require modifying the FTL's firmware code, which is hard in practice because the traditional block-based FTL does not provide an interface to modify its internal functions. New flash storage interface designs, such as open-channel SSDs or zoned namespaces, have moved key FTL functions into the OS. These interfaces ease modification of FTL functions, at the cost of blurring the trusted boundary, as the FTL is no longer isolated from the OS. In this work, we have introduced SxSSD, a secure yet extensible software-defined SSD design. By decoupling internal policy definitions from primitive FTL mechanisms, we allow trusted applications to dynamically and securely define FTL policies and the exposed storage interface (achieving increased flexibility compared to open-channel and zoned namespaces SSDs). Most significantly, SxSSD retains the isolation of traditional FTL execution (achieving security similar to traditional block-based SSDs). We have identified and addressed key security challenges introduced under a compromised OS. In addition, we have implemented a prototype of SxSSD and evaluated its overhead with different FTL policies and storage interfaces. Experimental evaluation demonstrates that the overhead incurred by SxSSD is small compared to native FTL implementations.