PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
October 19, 20255 citationsOpen Access

Efficient Security Support for CXL Memory through Adaptive Incremental Offloaded (Re-)Encryption

View Full Paper
CLChuanhan LiJZJishen ZhaoYXYuanchao Xu

Key Points

  • AIORE significantly reduces overall security overhead while enhancing encryption efficiency in CXL memory systems.
  • The performance overhead is maintained within 3.7% compared to an insecure baseline, ensuring robust operations.
  • Evaluation was conducted using the Gem5 simulator across diverse memory-intensive benchmarks for accuracy.
  • Adaptive encryption schemes allow for dynamic selections based on page access frequency to optimize performance.

Abstract

Current DRAM technologies face critical scaling limitations, significantly impacting the expansion of memory bandwidth and capacity required by modern data-intensive applications. Compute eXpress Link (CXL) emerges as a promising technology to address these limitations, enabling efficient cache-coherent memory expansion through direct connections between processors and CXL memory devices. Despite its potential, broad adoption of CXL memory in public cloud computing introduces substantial security challenges. Trusted Execution Environments (TEEs), such as Intel SGX/TDX and AMD SEV, provide robust protection for data integrity and confidentiality in cloud environments, complemented by CXL Integrity and Data Encryption (CXL IDE), which employs XTS encryption and Galois/Counter Mode (GCM) for secure message transmission.However, this approach incurs significant performance overhead due to the latency of XTS encryption on memory-intensive workloads. To mitigate this, we propose Adaptive Incremental Offloaded (Re-)Encryption (AIORE), an adaptive security framework combining Counter (CTR) and XTS encryption. AIORE dynamically selects encryption schemes based on page access frequency, implements incremental and offloaded re-encryption strategies, and leverages memory node computation to reduce overheads. Evaluation with Gem5 across diverse benchmarks reveals that AIORE significantly reduces security overhead by 62.8% on average and maintains overhead within 3.7% relative to an insecure baseline.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Li et al. (2025) studied this question.

synapsesocial.com/papers/68f4b10d3d9d770bbc696dc7https://doi.org/10.1145/3725843.3756119
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Denial of service in sensor networks2002 · 1,722 citations
  2. 2Memory Encryption for General-Purpose Processors2016 · 108 citations
  3. 3LVI: Hijacking Transient Execution through Microarchitectural Load Value Injection2020 · 207 citations
  4. 4A secure processor architecture for encrypted computation on untrusted programs2012 · 188 citations
  5. 5Architectural support for copy and tamper resistant software2000 · 123 citations