arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

ANCHOR:面向解聚数据中心中安全持久化键值存储的愿景

ANCHOR: A Vision for Secure Persistent Key-Value Stores in Disaggregated Data Centers

Viraj Thakkar, Dongha Kim, Hokeun Kim, Zhichao Cao

arXiv 2608.27819首次发表:更新:

AI 中文总结

针对解聚数据中心中PKVS的安全问题,本文提出ANCHOR架构,通过语义感知的持久化与易失性路径设计,结合TEE技术保障数据完整性与新鲜度,同时优化验证开销以保留解聚的性能优势。

AI 中文摘要

持久化键值存储(PKVS)越来越多地部署在解聚环境中,该环境将计算、内存和存储拆分到独立的服务器池。这种转变重新划定了信任边界:原本驻留在单台机器内的数据现在会在多台主机间传输、缓存和重写,从而扩大了网络攻击者和基础设施内部攻击者的暴露面。本文提出ANCHOR,一种解聚PKVS中端到端完整性和新鲜度的愿景。ANCHOR提出了两部分语义感知架构:1)持久化路径:ANCHOR概述了对PKVS持久化文件进行加密和认证,并通过清单版本控制防止回滚;2)易失性路径:ANCHOR将缓存、索引和过滤器视为不可信提示,除非有可验证的来源,这由TEE驻留策略强制执行。最后,我们概述了关键不变量,并讨论了适合飞地(enclave)的批处理和异步I/O,以在不损害解聚的性能和弹性优势的情况下摊销验证开销。

英文摘要

Persistent key-value stores (PKVS) are increasingly deployed in disaggregated settings that split compute, memory, and storage across separate server pools. This shift redraws the trust boundary: data that would remain within a single machine is now transported, cached, and rewritten across multiple hosts, expanding exposure to both network attackers and intra-infrastructure adversaries. This paper presents ANCHOR, a vision for end-to-end integrity and freshness in disaggregated PKVS. ANCHOR proposes a two-part semantics-aware architecture: 1) Persistence path: ANCHOR outlines encrypting and authenticating PKVS persistent files and preventing rollback with manifest versioning. 2) Volatile path: ANCHOR treats caches, indexes, and filters as untrusted hints unless accompanied by verifiable provenance, enforced by a TEE-resident policy. Finally, we outline key invariants and discuss enclave-friendly batching and asynchronous I/O to amortize verification without undermining disaggregation's performance and elasticity benefits.

DOI:10.1145/3807894.3810275

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑