arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

可信硬件加速用于恶意安全函数秘密共享

Trusted Hardware Acceleration for Malicious-Secure Function Secret Sharing

Yujie Xue, Yijing Peng, Lin Liu, Shaojing Fu, Shaoqing Li, Yaohua Wang, Rongmao Chen, Yang Guo

arXiv 2610.04818首次发表:更新:

发表机构

National University of Defense Technology(国防科技大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

提出VIGOR-DFA,一种GPU集成加速器,通过认证尾声、冻结检查及资源账本机制,在恶意安全下消除FSS密钥移动,显著降低延迟和能耗。

AI 中文摘要

函数秘密共享(FSS)是两方私有推理和私有信息检索的基础,其成本主要由分布式点函数(DPF)密钥的生成、移动和评估所主导。一个可信的GPU集成分布式函数加速器(DFA)通过在本地生成和消费密钥来消除密钥移动,但仅容忍半诚实对手。恶意主机或GPU可能篡改份额、重放一次性材料、在检查后交换缓冲区、请求早期输出,或将加速器滥用为伪造预言机,而恶意FSS则传输大型认证密钥或使DPF工作量倍增。我们提出VIGOR-DFA,通过三种机制保护从授权输入到授权输出发布的链条:一个使用每个DPF输出三次域乘法的全新认证尾声,每门比每通道DPF标签树快3.8-4.0倍;一个在挑战前冻结的检查,对每个开放在F_{2^61-1}上使用t=3个独立MAC通道;以及一个在GPU L2缓存旁受保护数据路径中带有发布守卫的角色绑定一次性资源账本。我们在受保护模块模型中证明了带中止的静态恶意安全性,对于Q≤2^32个检查批次,统计误差为Q(2/p)^t约2^-148。我们的DFA校准模型显示,针对基于Shark协议族的经销商型恶意FSS,VIGOR-DFA消除了每查询21.8-563 GB的离线认证材料,主要通过模块内生成,将LAN延迟降低10.1-14.0倍(排除离线分发为1.5-1.8倍),能耗降低3.0-3.9倍。恶意安全性相对于半诚实DFA使LAN延迟增加2.5-3.5倍,并在7 nm工艺下增加0.145 mm^2面积。我们已完成规格和功能CPU参考模型的验证,包括GPU/RTL一致性验证、受保护运行时评估和部署相关测试。

英文摘要

Function secret sharing (FSS) underlies two-party private inference and private information retrieval, with cost dominated by generating, moving and evaluating distributed point function (DPF) keys. A trusted GPU-integrated distributed function accelerator (DFA) removed key movement by generating and consuming keys locally, but tolerates only semi-honest adversaries. A malicious host or GPU can tamper with shares, replay one-time material, swap buffers after checking, request early outputs, or abuse the accelerator as a forgery oracle, while malicious FSS ships large authenticated keys or multiplies DPF work. We present VIGOR-DFA, protecting the chain from authorized input to authorized output release with three mechanisms: a fresh authentication epilogue using three field multiplications per DPF output, 3.8-4.0 times faster per gate than per-lane DPF tag trees; a freeze-before-challenge check of every opening with t = 3 independent MAC lanes over F_{2^61-1}; and a role-bound one-time resource ledger with a release guard, in a protected datapath beside the GPU L2 cache. We prove stand-alone static malicious security with abort in a protected-module model, with statistical error Q(2/p)^t approximately 2^-148 for Q less than or equal to 2^32 checked batches. Our DFA-calibrated model shows that, against dealer-based malicious FSS modeled after the protocol family of Shark, VIGOR-DFA removes 21.8-563 GB of per-query offline authenticated material and, mainly by generating it in-module, lowers LAN latency by 10.1-14.0 times (1.5-1.8 times excluding offline distribution) and energy by 3.0-3.9 times. Malicious security costs 2.5-3.5 times LAN latency over semi-honest DFA and 0.145 mm^2 at 7 nm. We have completed the verification of specifications and the functional CPU reference model, including GPU/RTL conformance verification, protected runtime evaluation, and deployment-related tests.

Comments62 pages, 18 figures, 15 tables. Preprint

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑