Advanced search
Start date
Betweenand


To Embed or Not to Embed SHA in Programmable Network Interface Cards

Full text
Author(s):
Show less -
Mafioletti, Diego Rossi ; Martinello, Magnos ; Ribeiro, Moises R. N. ; Ruffini, Marco ; Slyne, Frank ; IEEE ; Charalambides, M ; Papadimitriou, P ; Cerroni, W ; Kanhere, S ; Mamatas, L
Total Authors: 11
Document type: Journal article
Source: 2022 18TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM 2022): INTELLIGENT MANAGEMENT OF DISRUPTIVE NETWORK TECHNOLOGIES AND SERVICES; v. N/A, p. 7-pg., 2022-01-01.
Abstract

Cryptographic hash functions are widely used to provide from digital time stamping to authenticity and digital signatures, mapping an extensive collection of messages into a small set of message digests and help to secure network connection and data, consequently consuming CPU resources. P4 enables data plane customisation using a high-level programming language to facilitate in-network computing development across diverse hardware targets, including Network Interface Cards (NICs). Currently, most P4 targets do not implement secure hash functions due to a lack of hardware instructions or the absence of formal functions to expose their native hardware-based implementation. Moreover, many applications and protocols cannot be instantiated using in-network computing due to stringent requirements based on these hash functions. In order to empower the security and other hash-based applications, in this paper we propose and implement a P4 shared object library for a secure hash algorithm 2 (SHA-2). Our goal is to enable SHA-2 to be used as an embedded Network Function (eNF), overcoming the lack of support in a SmartNIC architecture, in order to address the latency and throughput requirements of Service Function Chain (SFC) forwarding performance within the Network Function Virtualization (NFV) paradigm. Thus, our prototype is evaluated against kernel-level Open vSwitch (OvS) and user-space Data Plane Development Kit (DPDK) implementations. The outcomes demonstrate different tradeoffs over each platform, from the randomness added by the OS to the high cost of executing the aforesaid function using a network programmable device, leading us to highlight the best choice for each specific application. (AU)

FAPESP's process: 18/23097-3 - SFI2: slicing future internet infrastructures
Grantee:Tereza Cristina Melo de Brito Carvalho
Support Opportunities: Research Projects - Thematic Grants
FAPESP's process: 20/05182-3 - PORVIR-5G: programability, orchestration and virtualization in 5G networks
Grantee:José Marcos Silva Nogueira
Support Opportunities: Research Projects - Thematic Grants