Designing Transport-Level Encryption for Datacenter Networks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Gao, Tianyi, Ma, Xinshu, Narreddy, Suhas, Luo, Eugenio, Chien, Steven W. D., Honda, Michio
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915795106267136
author Gao, Tianyi
Ma, Xinshu
Narreddy, Suhas
Luo, Eugenio
Chien, Steven W. D.
Honda, Michio
author_facet Gao, Tianyi
Ma, Xinshu
Narreddy, Suhas
Luo, Eugenio
Chien, Steven W. D.
Honda, Michio
contents Cloud applications need network data encryption to isolate from other tenants and protect their data from potential eavesdroppers in the network infrastructure. This paper presents SMT, a protocol design for emerging datacenter transport protocols, such as NDP and Homa, to integrate data encryption. SMT integrates TLS-based encryption with a message-based transport protocol that supports efficient Remote Procedure Calls (RPCs), a common workload in datacenters. This architecture enables the use of per-message record sequence number spaces in a secure session, while ensuring unique message identities to prevent replay attacks. It also enables the use of existing NIC offloads designed for TLS over TCP, while being a native transport protocol alongside TCP and UDP. We implement SMT in the Linux kernel by extending Homa/Linux and improve RPC throughput by up to 41 % and latency by up to 35 % in comparison to TLS/TCP.
format Preprint
id arxiv_https___arxiv_org_abs_2406_15686
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Designing Transport-Level Encryption for Datacenter Networks
Gao, Tianyi
Ma, Xinshu
Narreddy, Suhas
Luo, Eugenio
Chien, Steven W. D.
Honda, Michio
Cryptography and Security
Networking and Internet Architecture
Cloud applications need network data encryption to isolate from other tenants and protect their data from potential eavesdroppers in the network infrastructure. This paper presents SMT, a protocol design for emerging datacenter transport protocols, such as NDP and Homa, to integrate data encryption. SMT integrates TLS-based encryption with a message-based transport protocol that supports efficient Remote Procedure Calls (RPCs), a common workload in datacenters. This architecture enables the use of per-message record sequence number spaces in a secure session, while ensuring unique message identities to prevent replay attacks. It also enables the use of existing NIC offloads designed for TLS over TCP, while being a native transport protocol alongside TCP and UDP. We implement SMT in the Linux kernel by extending Homa/Linux and improve RPC throughput by up to 41 % and latency by up to 35 % in comparison to TLS/TCP.
title Designing Transport-Level Encryption for Datacenter Networks
topic Cryptography and Security
Networking and Internet Architecture
url https://arxiv.org/abs/2406.15686