TY - GEN
T1 - Fast & Safe IO Memory Protection
AU - Rubin, Benny
AU - Agarwal, Saksham
AU - Cai, Qizhe
AU - Agarwal, Rachit
N1 - We would like to thank our shepherd and SOSP reviewers for insightful feedback.We would also like to thank Midhul Vuppalapati for useful discussions. This research was in part supported by NSF grant CNS-2047283, and a Sloan fellowship.
PY - 2024/11/15
Y1 - 2024/11/15
N2 - IO Memory protection mechanisms prevent malicious and/or buggy IO devices from executing errant transfers into memory. Modern servers achieve this using an IOMMU - -IO devices operate on virtual addresses, and IOMMU translates virtual addresses to physical addresses (potentially speeding up translations using a cache called IOTLB) before executing memory transfers. Despite their importance, design of memory protection mechanisms that can provide strong safety properties while achieving high performance has remained elusive. Indeed, recent studies from production datacenters demonstrate that inefficiencies within state-of-the-art memory protection mechanisms result in significant throughput degradation, orders-of-magnitude tail latency inflation, and violation of isolation guarantees.We present Fast & Safe (F&S), a simple modification to existing memory protection mechanisms that enables them to provide the strongest safety property, and yet, near-completely eliminates their overheads. The key insight in F&S design is that, rather than solely focusing on minimizing IOTLB miss rates, we should focus on reducing the cost of each IOTLB miss. We demonstrate that this change of perspective enables a simple F&S design that requires no modifications in host hardware and minimal modifications within the operating system.
AB - IO Memory protection mechanisms prevent malicious and/or buggy IO devices from executing errant transfers into memory. Modern servers achieve this using an IOMMU - -IO devices operate on virtual addresses, and IOMMU translates virtual addresses to physical addresses (potentially speeding up translations using a cache called IOTLB) before executing memory transfers. Despite their importance, design of memory protection mechanisms that can provide strong safety properties while achieving high performance has remained elusive. Indeed, recent studies from production datacenters demonstrate that inefficiencies within state-of-the-art memory protection mechanisms result in significant throughput degradation, orders-of-magnitude tail latency inflation, and violation of isolation guarantees.We present Fast & Safe (F&S), a simple modification to existing memory protection mechanisms that enables them to provide the strongest safety property, and yet, near-completely eliminates their overheads. The key insight in F&S design is that, rather than solely focusing on minimizing IOTLB miss rates, we should focus on reducing the cost of each IOTLB miss. We demonstrate that this change of perspective enables a simple F&S design that requires no modifications in host hardware and minimal modifications within the operating system.
KW - IOMMU
KW - memory protection
UR - https://www.scopus.com/pages/publications/85215521477
UR - https://www.scopus.com/pages/publications/85215521477#tab=citedBy
U2 - 10.1145/3694715.3695943
DO - 10.1145/3694715.3695943
M3 - Conference contribution
AN - SCOPUS:85215521477
T3 - SOSP 2024 - Proceedings of the 2024 ACM SIGOPS 30th Symposium on Operating Systems Principles
SP - 95
EP - 109
BT - SOSP 2024 - Proceedings of the 2024 ACM SIGOPS 30th Symposium on Operating Systems Principles
PB - Association for Computing Machinery
T2 - 30th ACM Symposium on Operating Systems Principles, SOSP 2024
Y2 - 4 November 2024 through 6 November 2024
ER -