SADRA:面向资源解耦架构的基于能力的可靠访问控制系统
SADRA: Sound Capability-based Access Control System for Resource-Disaggregated Architectures
浏览论文内容
中文总结 AI 辅助
针对资源解耦架构中主机不可信带来的权限滥用问题,提出基于能力的分布式访问控制系统SADRA,利用SmartNIC在计算节点和资源处双重验证,实现可靠撤销与高性能。
中文摘要 AI 辅助
资源解耦将内存和加速器与计算节点分离,并使其可远程访问。这改善了资源共享,但也将本地内核从资源访问路径中移除。在不可信主机下,被攻陷的主机软件可能使用过期的权限、超出被授权的权限,或重用为其他进程提供的权限。先前的工作认为基于能力的访问控制非常适合这些架构。我们对二十二个先前能力系统的系统化研究发现,没有一个系统能同时具备主机无关的进程权限验证、在资源处的权威执行,以及在远程授权状态过期时仍然有效的撤销机制。我们提出了SADRA,一个面向资源解耦架构的分布式基于能力的访问控制系统。与主机软件隔离的SmartNIC硬件在两点独立检查每个节点间请求,首先在计算节点处对照请求进程的权限,其次在资源处对照当前的权威访问状态。链接的进程、计算和资源能力使得这些检查能够在不协调访问路径的情况下使用本地状态。当分布式权限被撤销时,SADRA在资源处拒绝后续依赖访问,无需等待远程节点更新,而过期的能力状态则被单独回收。我们为一个正式架构模型证明了能力安全性、权限安全性、撤销可靠性和强隔离性,并使用SPIN对形式化进行了模型检查。我们的FPGA SmartNIC原型维持89.5 Gbit/s的聚合吞吐量,在非执行基线(峰值90-91 Gbit/s)的运行间波动范围内。清理一个128能力的子树在528纳秒内完成,而访问拒绝不依赖于该清理的完成。
英文摘要
Resource disaggregation separates memory and accelerators from compute nodes and makes them remotely accessible. This improves resource sharing, but also removes the local kernel from the resource-access path. Under an untrusted host, compromised host software may use stale authority, exceed delegated authority, or reuse authority provisioned for another process. Prior work identifies capability-based access control as well suited to these architectures. Our systematization of twenty-two prior capability systems finds that none combines host-independent validation of process authority, authoritative enforcement at the resource, and revocation that remains effective while remote authorization state is stale. We present SADRA, a distributed capability-based access-control system for resource-disaggregated architectures. SmartNIC hardware isolated from host software independently checks every inter-node request at two points, first at the compute node against the requesting process's authority and again at the resource against the current authoritative access state. Linked process, compute, and resource capabilities allow these checks to use local state without coordination on the access path. When distributed authority is revoked, SADRA denies subsequent dependent accesses at the resource without waiting for remote nodes to update, while stale capability state is reclaimed separately. We prove capability safety, authority safety, revocation soundness, and strong isolation for a formal architectural model, and model-check the formalization with SPIN. Our FPGA SmartNIC prototype sustains 89.5 Gbit/s aggregate throughput, within run-to-run variation of a non-enforcing baseline that peaks at 90--91 Gbit/s. Cleanup of a 128-capability subtree completes in 528 ns, while access denial does not depend on completion of that cleanup.
发表机构
- Saarland University(萨尔兰大学)
- CISPA Helmholtz Center for Information Security(CISPA赫尔霍兹信息安全中心)
- KTH Royal Institute of Technology(皇家理工学院)
机构由 AI 辅助整理,请以论文原文为准。