🤖 AI Summary
This work addresses the high key transmission overhead of function secret sharing and the tamper vulnerability of hardware accelerators in malicious settings by proposing VIGOR-DFA, a trusted acceleration architecture. VIGOR-DFA performs local key generation and consumption via a GPU bypass, integrating a lightweight authentication epilogue, pre-freeze challenge checks, and a role-bound one-time resource ledger. By leveraging distributed point functions and finite-field MAC verification, it achieves low-overhead protection under static malicious security. Experimental results demonstrate that this approach eliminates hundreds of gigabytes of offline authentication material, reduces network latency by over 10×, decreases energy consumption by nearly 4×, and incurs a minimal hardware area overhead of only 0.145 mm².
📝 Abstract
Function secret sharing (FSS) underlies two-party private inference and private information retrieval, with cost dominated by generating, moving and evaluating distributed point function (DPF) keys. A trusted GPU-integrated distributed function accelerator (DFA) removed key movement by generating and consuming keys locally, but tolerates only semi-honest adversaries. A malicious host or GPU can tamper with shares, replay one-time material, swap buffers after checking, request early outputs, or abuse the accelerator as a forgery oracle, while malicious FSS ships large authenticated keys or multiplies DPF work. We present VIGOR-DFA, protecting the chain from authorized input to authorized output release with three mechanisms: a fresh authentication epilogue using three field multiplications per DPF output, 3.8-4.0 times faster per gate than per-lane DPF tag trees; a freeze-before-challenge check of every opening with t = 3 independent MAC lanes over F_{2^61-1}; and a role-bound one-time resource ledger with a release guard, in a protected datapath beside the GPU L2 cache. We prove stand-alone static malicious security with abort in a protected-module model, with statistical error Q(2/p)^t approximately 2^-148 for Q less than or equal to 2^32 checked batches. Our DFA-calibrated model shows that, against dealer-based malicious FSS modeled after the protocol family of Shark, VIGOR-DFA removes 21.8-563 GB of per-query offline authenticated material and, mainly by generating it in-module, lowers LAN latency by 10.1-14.0 times (1.5-1.8 times excluding offline distribution) and energy by 3.0-3.9 times. Malicious security costs 2.5-3.5 times LAN latency over semi-honest DFA and 0.145 mm^2 at 7 nm. We have completed the verification of specifications and the functional CPU reference model, including GPU/RTL conformance verification, protected runtime evaluation, and deployment-related tests.