🤖 AI Summary
This study addresses the security risks—such as privilege expiration, unauthorized escalation, and capability reuse—introduced by untrusted hosts in resource disaggregation architectures. To mitigate these threats, this work proposes a SmartNIC-based distributed capability access control system. The system introduces a novel capability mechanism that integrates host-independent verification, authoritative execution at the resource side, and efficient revocation. By leveraging FPGA hardware isolation, it enables independent privilege validation and secure revocation across compute and resource nodes, supported by a formal security proof. Experimental evaluation of the prototype demonstrates a throughput of 89.5 Gbit/s, with the revocation of a 128-node capability subtree requiring only 528 nanoseconds. These results confirm that the proposed architecture successfully unifies high performance with robust security isolation for disaggregated systems.
📝 Abstract
Resource disaggregation separates memory and accelerators from compute nodes and makes them remotely accessible. This improves resource sharing, but also removes the local kernel from the resource-access path. Under an untrusted host, compromised host software may use stale authority, exceed delegated authority, or reuse authority provisioned for another process. Prior work identifies capability-based access control as well suited to these architectures. Our systematization of twenty-two prior capability systems finds that none combines host-independent validation of process authority, authoritative enforcement at the resource, and revocation that remains effective while remote authorization state is stale.
We present SADRA, a distributed capability-based access-control system for resource-disaggregated architectures. SmartNIC hardware isolated from host software independently checks every inter-node request at two points, first at the compute node against the requesting process's authority and again at the resource against the current authoritative access state. Linked process, compute, and resource capabilities allow these checks to use local state without coordination on the access path. When distributed authority is revoked, SADRA denies subsequent dependent accesses at the resource without waiting for remote nodes to update, while stale capability state is reclaimed separately.
We prove capability safety, authority safety, revocation soundness, and strong isolation for a formal architectural model, and model-check the formalization with SPIN. Our FPGA SmartNIC prototype sustains 89.5 Gbit/s aggregate throughput, within run-to-run variation of a non-enforcing baseline that peaks at 90--91 Gbit/s. Cleanup of a 128-capability subtree completes in 528 ns, while access denial does not depend on completion of that cleanup.