DF-TEE: Trusted Execution Environment for Disaggregated Multi-FPGA Cloud Systems

Ke Xia, Sheng Wei · 2023

Multi-FPGA systems have recently been deployed in modern data centers to accelerate large-scale, computation-intensive cloud applications. Meanwhile, recent studies promote resource disaggregation as an emerging trend in data center infrastructure enabling high flexibility and utilization of cloud computing resources, including FPGAs. While the community has mostly focused on the management and performance optimization aspects of disaggregated multi-FPGA systems, the security challenges caused by the emerging infrastructure have not been well studied. We tackle the security of disaggregated multi-FPGA systems by developing a new trusted execution environment (TEE), namely DF-TEE, which for the first time extends the capability of the traditional CPU TEEs to disaggregated FPGA accelerators. DF-TEE employs a secure isolation path to connect all the components in the CPU and multi-FPGA system based on the established mutual trust in the heterogeneous environment, as well as security-aware slicing and deployment of the sensitive computations. We evaluate DF-TEE on a real hardware implementation of disaggregated multi-FPGA system, which justifies its security with acceptable timing and resource overhead.

Read the paper · More papers on PaperTik