Research for secure on-chip isolated execution environment on commodity graphics processing units상용 GPU 에서 안전한 온칩 실행환경 구축을 위한 연구

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 183
  • Download : 0
In the last decade, the dedicated graphics processing unit (GPU) has emerged as an architecture for high-performance computing workloads. Recently, researchers have also focused on the isolation property of a dedicated GPU and suggested GPU-based secure computing environments with several promising applications. Through implementations and security analysis, they have claimed that a dedicated GPU can be leveraged as a secure processor in the presence of a kernel-privileged attacker. However, despite the security analysis conducted by the prior studies, it has been unclear whether a dedicated GPU can support secure execution environment against a kernel-privileged attacker. In this dissertation, we first investigate the security of dedicated GPUs through comprehensive studies on context information for GPU kernel execution. We show that a kernel-privileged attacker can manipulate the GPU contexts to redirect memory accesses or execute arbitrary GPU codes on the running GPU kernel. Furthermore, we introduce the installation method of stealthy rootkit hidden inside GPU kernel execution through GPU context manipulation. Based on our security analysis, we propose a new secure isolated on-chip execution model for the dedicated GPU and a novel defense mechanism supporting the security of the on-chip execution. Our solution operates on Nvidia commodity GPUs without any modification of the hardware or GPU driver and without an additional hardware-abstraction layer. With comprehensive evaluation, we assure that the proposed solutions effectively isolate sensitive information in on-chip storages and defend against known attack vectors from a privileged attacker, supporting that the commodity GPUs can be leveraged as a secure processor.
Advisors
Yoon, Hyunsooresearcher윤현수researcher
Description
한국과학기술원 :전산학부,
Publisher
한국과학기술원
Issue Date
2020
Identifier
325007
Language
eng
Description

학위논문(박사) - 한국과학기술원 : 전산학부, 2020.2,[iv, 58 p. :]

Keywords

Graphics processors▼aSecure systems▼aGPU security▼aOn-chip execution▼aReverse engineering; 그래픽 프로세서▼a보안 시스템▼aGPU 보안▼a온칩 실행▼a역공학 분석

URI
http://hdl.handle.net/10203/284159
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=909377&flag=dissertation
Appears in Collection
CS-Theses_Ph.D.(박사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0