Designing Transport-Level Encryption for Datacenter Networks

Tianyi Gao, Xinshu Ma, Suhas Narreddy, Eugenio Luo, Steven Chien, Michio Honda

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Cloud applications need network data encryption to isolate from other tenants and protect their data from potential eavesdroppers in the network infrastructure. This paper presents SDT, a protocol design for emerging datacenter
transport protocols, such as NDP and Homa, to integrate data encryption. SDT uses per-message record sequence number spaces in a secure session, which ensures unique message identities for its messages to prevent replay attacks. This design enables transport-level encryption that supports existing NIC offloads designed for TLS over TCP, native protocol number alongside TCP and UDP, and message-based abstraction that mitigates head-of-line blocking and enables the network or host stack to identify the message boundaries for load balancing. We implement SDT in the Linux kernel by extending Homa/Linux and improves RPC throughput by up to 41 % and latency by up to 35 % in comparison to TLS/TCP.
Original languageEnglish
Title of host publicationProceedings of the 9th Asia-Pacific Workshop on Networking
PublisherAssociation for Computing Machinery (ACM)
Pages142-149
Number of pages17
DOIs
Publication statusPublished - 6 Aug 2025
EventProceedings of the 9th Asia-Pacific Workshop on Networking - Shanghai, China
Duration: 7 Aug 20258 Aug 2025
Conference number: 9
https://conferences.sigcomm.org/events/apnet2025/index.php

Conference

ConferenceProceedings of the 9th Asia-Pacific Workshop on Networking
Abbreviated titleAPNET 25
Country/TerritoryChina
CityShanghai
Period7/08/258/08/25
Internet address

Keywords / Materials (for Non-textual outputs)

  • Security
  • Networking
  • Data center networks

Fingerprint

Dive into the research topics of 'Designing Transport-Level Encryption for Datacenter Networks'. Together they form a unique fingerprint.

Cite this