AI 中文总结
针对解聚数据中心中PKVS的安全问题,本文提出ANCHOR架构,通过语义感知的持久化与易失性路径设计,结合TEE技术保障数据完整性与新鲜度,同时优化验证开销以保留解聚的性能优势。
AI 中文摘要
持久化键值存储(PKVS)越来越多地部署在解聚环境中,该环境将计算、内存和存储拆分到独立的服务器池。这种转变重新划定了信任边界:原本驻留在单台机器内的数据现在会在多台主机间传输、缓存和重写,从而扩大了网络攻击者和基础设施内部攻击者的暴露面。本文提出ANCHOR,一种解聚PKVS中端到端完整性和新鲜度的愿景。ANCHOR提出了两部分语义感知架构:1)持久化路径:ANCHOR概述了对PKVS持久化文件进行加密和认证,并通过清单版本控制防止回滚;2)易失性路径:ANCHOR将缓存、索引和过滤器视为不可信提示,除非有可验证的来源,这由TEE驻留策略强制执行。最后,我们概述了关键不变量,并讨论了适合飞地(enclave)的批处理和异步I/O,以在不损害解聚的性能和弹性优势的情况下摊销验证开销。
英文摘要
Persistent key-value stores (PKVS) are increasingly deployed in disaggregated settings that split compute, memory, and storage across separate server pools. This shift redraws the trust boundary: data that would remain within a single machine is now transported, cached, and rewritten across multiple hosts, expanding exposure to both network attackers and intra-infrastructure adversaries. This paper presents ANCHOR, a vision for end-to-end integrity and freshness in disaggregated PKVS. ANCHOR proposes a two-part semantics-aware architecture: 1) Persistence path: ANCHOR outlines encrypting and authenticating PKVS persistent files and preventing rollback with manifest versioning. 2) Volatile path: ANCHOR treats caches, indexes, and filters as untrusted hints unless accompanied by verifiable provenance, enforced by a TEE-resident policy. Finally, we outline key invariants and discuss enclave-friendly batching and asynchronous I/O to amortize verification without undermining disaggregation's performance and elasticity benefits.