ShieldBox: Secure Middleboxes Using Shielded Execution
Publikation: Beitrag zu Konferenzen › Paper › Beigetragen › Begutachtung
Beitragende
Abstract
Middleboxes that process confidential data cannot be securely deployed in untrusted cloud environments. To securely outsource middleboxes to the cloud, state-of-the-art systems advocate network processing over the encrypted traffic. Unfortunately, these systems support only restrictive functionalities, and incur prohibitively high overheads.
This motivated the design of ShieldBox---a secure middlebox framework for deploying high-performance network functions (NFs) over untrusted commodity servers. ShieldBox securely processes encrypted traffic inside a secure container by leveraging shielded execution. More specifically, ShieldBox builds on hardware-assisted memory protection based on Intel SGX to provide strong confidentiality and integrity guarantees. For middlebox developers, ShieldBox exposes a generic interface based on Click to design and implement a wide-range of NFs using its out-of-the-box elements and C++ extensions. For network operators, ShieldBox provides configuration and attestation service for seamless and verifiable deployment of middleboxes. We have implemented ShieldBox supporting important end-to-end features required for secure network processing, and performance optimizations. Our extensive evaluation shows that ShieldBox achieves a near-native throughput and latency to securely process confidential data at line rate.
This motivated the design of ShieldBox---a secure middlebox framework for deploying high-performance network functions (NFs) over untrusted commodity servers. ShieldBox securely processes encrypted traffic inside a secure container by leveraging shielded execution. More specifically, ShieldBox builds on hardware-assisted memory protection based on Intel SGX to provide strong confidentiality and integrity guarantees. For middlebox developers, ShieldBox exposes a generic interface based on Click to design and implement a wide-range of NFs using its out-of-the-box elements and C++ extensions. For network operators, ShieldBox provides configuration and attestation service for seamless and verifiable deployment of middleboxes. We have implemented ShieldBox supporting important end-to-end features required for secure network processing, and performance optimizations. Our extensive evaluation shows that ShieldBox achieves a near-native throughput and latency to securely process confidential data at line rate.
Details
| Originalsprache | Englisch |
|---|---|
| Seiten | 1-14 |
| Publikationsstatus | Veröffentlicht - 2018 |
| Peer-Review-Status | Ja |
Konferenz
| Titel | 2018 USENIX Annual Technical Conference |
|---|---|
| Kurztitel | USENIX ATC 18 |
| Beschreibung | Co-located Events: HotStorage '18: 10th USENIX Workshop on Hot Topics in Storage and File Systems (July 9–10, 2018) HotCloud '18: 10th USENIX Workshop on Hot Topics in Cloud Computing (July 9, 2018) HotEdge '18: USENIX Workshop on Hot Topics in Edge Computing (July 10, 2018) |
| Dauer | 11 - 13 Juli 2018 |
| Webseite | |
| Bekanntheitsgrad | Internationale Veranstaltung |
| Ort | Westin Copley Place Boston |
| Stadt | Boston |
| Land | USA/Vereinigte Staaten |