首页 /研究 /Space-Control: Process-Level Isolation for Sharing CXL-based Disaggregated Memory
OTHER

Space-Control: Process-Level Isolation for Sharing CXL-based Disaggregated Memory

Kaustav Goswami, Sean Peisert, Venkatesh Akella, Jason Lowe-Power

发表年份
2026
访问权限
开放获取

摘要

Memory disaggregation via CXL enables multi-host resource sharing. However, existing CXL sharing mechanisms enforce coarse-grained, host-level permissions only, leaving isolation to the operating system. Today, virtual memory enables process-level isolation on a host and CXL enables host-level isolation. This creates a critical security gap: the absence of process-level memory isolation in shared disaggregated memory. We present Space-Control, an architectural abstraction that introduces a cross-host identity primitive to enforce confidentiality and integrity. We decouple authorization from the untrusted OS using a hardware-rooted validation engine (SPACE) to establish immutable process identity and a Permission Checker at the memory egress point for fine-grained permission validation. Our design supports 127 concurrent processes across 255 hosts with only 1.56% storage overhead. Cycle-level evaluation using gem5 + SST shows that Space-Control incurs a minimal 3.3% performance penalty with a modest 16 KiB cache, providing a practical and scalable foundation for secure, process-level memory disaggregation.

关键词

cs.ARcs.CReess.SY

相关论文

查看 OTHER 分类全部论文