DPU for Cybersecurity:Enabling Inline Defense and Self-ProtectionOA
As conventional CPU-based security architectures struggle to scale with ever-growing network bandwidths and increasingly sophisticated cyberattacks,the data processing unit(DPU),a specialized processor for datacenter infrastructure,has emerged as a transformative foundation for secure and high-performance computing.Unlike prior fragmented studies,this work proposes a comprehensive security framework for DPUs by systematically investigating the DPUs''dual role in cybersecurity,serving both as an active security enforcer and as a critical component that must itself be protected.First,the framework offloads security policies onto the DPU to enable line-rate packet inspection and hardware-accelerated security processing.Second,the framework re-architects the DPU itself to defend against physical and architectural attacks,acknowledging that the DPU also introduces a new attack surface.We validate these two design directions through two representative case studies,demonstrating the effectiveness and practicality of the proposed DPU security framework.Experimental results show that the proposed framework reduces remote direct memory access(RDMA)cache side-channel detection latency by up to 98.7%compared with the state-of-the-art,while enabling a trusted execution environment on field-programmable gate array(FPGA)-based DPUs with sub-100 ns overhead and less than 4%FPGA resource consumption.
Xiao-Wei Li;Yun-Kun Liao;Gui-Hai Yan
State Key Laboratory of Processors,Institute of Computing Technology,Chinese Academy of Sciences,Beijing 100190,ChinaState Key Laboratory of Processors,Institute of Computing Technology,Chinese Academy of Sciences,Beijing 100190,China University of Chinese Academy of Sciences,Beijing 100049,ChinaState Key Laboratory of Processors,Institute of Computing Technology,Chinese Academy of Sciences,Beijing 100190,China YUSUR Technology Co.,Ltd.,Beijing 100094,China
信息技术与安全科学
cybersecurityconfidential computingdata processing unitremote direct memory access
《Journal of Computer Science & Technology》 2026 (1)
P.114-127,14
supported by the Strategic Priority Research Program of the Chinese Academy of Sciences under Grant No.XDB0660102the National Natural Science Foundation of China under Grant Nos.62090024,92373206,62090020.
评论