High-speed security middleboxes on heterogeneous programmable data plane devices

项目来源

日本学术振兴会基金(JSPS)

项目主持人

小泉 佑揮

项目受资助机构

大阪大学

项目编号

24K02930

立项年度

2024

立项时间

未公开

项目级别

国家级

研究期限

未知 / 未知

受资助金额

18590000.00日元

学科

情報ネットワーク関連

学科代码

未公开

基金类别

基盤研究(B)

关键词

プログラマブルスイッチ ; スマートNIC ; セキュリティー ; ミドルボックス ;

参与者

武政淳二

参与机构

未公开

项目标书摘要:Outline of Research at the Start:本課題では、性質の異なる多様なプログラマブルデータプレーンのハードウェア技術を融合することで、1 Tbps級のパケット転送が可能な超高速なセキュリティーミドルボックスの構成を目的とし、異種ハードウェア技術の特性を正確に把握する実験的研究、それらを融合した際の最適な機能配置を導出する理論的研究、ハードウェアの性能差を吸収する機構を開発する技術的研究、異種プログラマブルデータプレーンハードウェア上のセキュリティーミドルボックスに適したプロトコルを設計するネットワークプロトコル的な研究、そして、それらをテストベッドで実証する実践的な研究に取り組む。

  • 排序方式:
  • 1
  • /
  • 1.BalancedSecAgg: Toward Fast Secure Aggregation for Federated Learning

    • 关键词:
    • Servers; Costs; Protocols; Computational modeling; Privacy; Data models;Vectors; Polynomials; Federated learning; Training data; Data privacy;Dropout tolerance; federated learning; privacy preservation; secureaggregation
    • Masuda, Hiroki;Kita, Kentaro;Koizumi, Yuki;Takemasa, Junji;Hasegawa, Toru
    • 《IEEE ACCESS》
    • 2024年
    • 12卷
    • 期刊

    Federated learning is a promising collaborative learning system from the perspective of training data privacy preservation; however, there is a risk of privacy leakage from individual local models of users. Secure aggregation protocols based on local model masking are a promising solution to prevent privacy leakage. Existing secure aggregation protocols sacrifice either computation or communication costs to tolerate user dropouts. A naive secure aggregation protocol achieves a small communication cost by secretly sharing random seeds instead of random masks. However, it requires that a server incurs a substantial computation cost to reconstruct the random masks from the random seeds of dropout users. To avoid such a reconstruction, a state-of-the-art secure aggregation protocol secretly shares random masks. Although this approach avoids the computation cost of mask reconstruction, it incurs a large communication cost due to secretly sharing random masks. In this paper, we design a secure aggregation protocol to mitigate the tradeoff between the computation cost and the communication cost by complementing both types of secure aggregation protocols. In our experiments, our protocol achieves up to 11.41 times faster while achieving the same level of privacy preservation and dropout tolerance as the existing protocols.

    ...
  • 2.High-Throughput Stateless-but-Complex Packet Processing within a Tbps Programmable Switch

    • 关键词:
    • Packet networks;Bandwidth consumption;High-throughput;In networks;In-network computations;In-network computing;Network computing;Packet header;Packet processing;Packet recirculation;Programmable switches
    • Yoshinaka, Yutaro;Koizumi, Yuki;Takemasa, Junji;Hasegawa, Toru
    • 《32nd IEEE International Conference on Network Protocols, ICNP 2024》
    • 2024年
    • October 28, 2024 - October 31, 2024
    • Charleroi, Belgium
    • 会议

    Programmable switches are promising platforms for fast and flexible in-network computation; however, a standard mechanism, packet recirculation, degrades throughput due to bandwidth consumption caused by the loopback of not only packet headers but also cumbersome payloads. This paper proposes P4QRS, a mechanism for retaining payloads within the switch, reducing payload recirculations. Specifically, P4QRS bifurcates packets into headers and payloads, which undergo the computation process through pipelines and the buffering process leveraging the switch’s queue behavior, respectively; they then rendezvous for reassembly into complete packets to be sent out. To validate its effectiveness, we evaluated P4QRS using an analytical model and implementation on state-of-the-art hardware programmable switches. Our evaluation shows that P4QRS operates stably and intrinsically boosts complex in-switch computations. © 2024 IEEE.

    ...
  • 排序方式:
  • 1
  • /