Seongwook Jin

dblp:03/9080 · DBLP profile ↗
← Back
12ranked-venue papers
4as first author
1since 2021 · last 2021
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 9 · 4 first-author · 1 since 2021Software engineering, systems software and programming languages · 3 · 1 since 2021Security and privacy · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer architecture, parallel and distributed computing, and storage systems
6 papers
Cloud and datacenter computing · 41% Memory systems · 39% Distributed systems · 15%
Network and information security
4 papers
Hardware security and side channels · 78% Systems and software security · 22%

Topics — the 18 heaviest of 20, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Hardware security and side channels
trusted execution environments
0.532016
A Trusted IaaS Environment with Hardware Security Module · IEEE Trans. Serv. Comput. 2016
H-SVM: Hardware-Assisted Secure Virtual Machines under a Vulnerable Hypervisor · IEEE Trans. Computers 2015
Architectural support for secure virtualization under a vulnerable hypervisor · MICRO 2011
Hardware security and side channels › side-channel countermeasures
access pattern obfuscation
0.512021
Ghost Routing to Enable Oblivious Computation on Memory-centric Networks · ISCA 2021
Distributed systems
oblivious computation
0.512021
Ghost Routing to Enable Oblivious Computation on Memory-centric Networks · ISCA 2021
Memory systems
processing-in-memory
0.512021
Ghost Routing to Enable Oblivious Computation on Memory-centric Networks · ISCA 2021
Cloud and datacenter computing
virtualization
0.532015
Fast Two-Level Address Translation for Virtualized Systems · IEEE Trans. Computers 2015
Revisiting hardware-assisted page walks for virtualized systems · ISCA 2012
Architectural support for secure virtualization under a vulnerable hypervisor · MICRO 2011
Memory systems › memory management
virtual memory
0.422015
Fast Two-Level Address Translation for Virtualized Systems · IEEE Trans. Computers 2015
Revisiting hardware-assisted page walks for virtualized systems · ISCA 2012
Systems and software security
virtualization security
0.322015
H-SVM: Hardware-Assisted Secure Virtual Machines under a Vulnerable Hypervisor · IEEE Trans. Computers 2015
Architectural support for secure virtualization under a vulnerable hypervisor · MICRO 2011
Hardware security and side channels › cryptographic hardware
hardware security module
0.212016
A Trusted IaaS Environment with Hardware Security Module · IEEE Trans. Serv. Comput. 2016
Hardware security and side channels › trusted execution environments
hardware-assisted memory isolation
0.212015
H-SVM: Hardware-Assisted Secure Virtual Machines under a Vulnerable Hypervisor · IEEE Trans. Computers 2015
Cloud and datacenter computing › virtualization
memory virtualization
0.212015
Fast Two-Level Address Translation for Virtualized Systems · IEEE Trans. Computers 2015
Memory systems › memory management › virtual memory
page table
0.212015
Fast Two-Level Address Translation for Virtualized Systems · IEEE Trans. Computers 2015
Cloud and datacenter computing › virtualization
hardware-assisted virtualization
0.112012
Revisiting hardware-assisted page walks for virtualized systems · ISCA 2012
Memory systems › virtual memory management
nested page table walk
0.112012
Revisiting hardware-assisted page walks for virtualized systems · ISCA 2012
Cloud and datacenter computing › virtualization › virtualization security
hypervisor security
0.112011
Architectural support for secure virtualization under a vulnerable hypervisor · MICRO 2011
Systems and software security
isolation
0.112016
A Trusted IaaS Environment with Hardware Security Module · IEEE Trans. Serv. Comput. 2016
Cloud and datacenter computing
cloud security
0.112015
H-SVM: Hardware-Assisted Secure Virtual Machines under a Vulnerable Hypervisor · IEEE Trans. Computers 2015
Cloud and datacenter computing › virtualization
virtual machine monitor
0.112015
Fast Two-Level Address Translation for Virtualized Systems · IEEE Trans. Computers 2015
Memory systems › memory management › virtual memory › address translation
TLB
0.012012
Revisiting hardware-assisted page walks for virtualized systems · ISCA 2012

Methods — techniques the papers use, named apart from their topics

source-based routing · 1.0random routing · 1.0ghost packets · 1.0trusted computing base minimization · 0.5hardware security module · 0.5system management mode · 0.4nested paging · 0.4architectural support · 0.2full-system simulation · 0.1
YearPublicationVenuePosition
2021 Ghost Routing to Enable Oblivious Computation on Memory-centric Networks
abstract
With offloading of data to the cloud, ensuring privacy and securing data has become more important. However, encrypting data alone is insufficient as the memory address itself can leak sensitive information. In this work, we exploit packetized memory interface to provide secure memory access and support oblivious computation in a system with multiple memory modules interconnected with a multi-hop, memory-centric network. While the memory address can be encrypted with a packetized memory interface, simply encrypting the address does not provide full oblivious computation since coarse-grain memory access patterns can be leaked. In this work, we first propose a scalable encryption microarchitecture with source-based routing where the packet is only encrypted once at source and latency overhead in intermediate routers is minimized. We then define secure routing in memory-centric networks to enable oblivious computation such that memory access patterns across the memory modules are completely obfuscated. We explore different naive secure routing algorithms to ensure oblivious computation but they come with high performance overhead. To minimize performance overhead, we propose ghost packets that replace dummy packets with existing network traffic. We also propose Ghost routing that batches multiple ghost packets together to minimize bandwidth loss from naive secure routing while exploiting random routing.
Yeonju Ro, Seongwook Jin, Jaehyuk Huh 0001, John Kim 0001
ISCA2
2017 On-demand virtualization for live migration in bare metal cloud
abstract
The level of demand for bare-metal cloud services has increased rapidly because such services are cost-effective for several types of workloads, and some cloud clients prefer a single-tenant environment due to the lower security vulnerability of such enviornments. However, as the bare-metal cloud does not utilize a virtualization layer, it cannot use live migration. Thus, there is a lack of manageability with the bare-metal cloud. Live migration support can improve the manageability of bare-metal cloud services significantly.
Jaeseong Im, Jongyul Kim 0001, Jonguk Kim, Seongwook Jin, Seung Ryoul Maeng
SoCC4
2016 On-demand bootstrapping mechanism for isolated cryptographic operations on commodity accelerators
Yonggon Kim, Ohmin Kwon 0001, Jin Soo Jang, Seongwook Jin, Hyeongboo Baek, Brent ByungHoon Kang, Hyunsoo Yoon
Comput. Secur.4
2016 A Trusted IaaS Environment with Hardware Security Module
abstract
With the proliferation of cloud computing, security concerns about confidentiality violations of user data by the privileged domain and system administrators have been growing. This paper proposes secure cloud architecture with a hardware security module, which isolates cloud user data from potentially malicious privileged domains or cloud administrators. Within a securely isolated execution environment, the hardware security module provides essential security functionality with only restricted interfaces exposed to vulnerable management systems or cloud administrators. Such restriction prevents cloud administrators from affecting the security of guest VMs. The proposed architecture not only defends against wide attack vectors but also achieves a small TCB. This paper discusses our hardware and software implementation of the proposed cloud architecture, analyzes its security, and presents its performance results.
Jinho Seol, Seongwook Jin, DaeWoo Lee, Jaehyuk Huh 0001, Seung Ryoul Maeng
IEEE Trans. Serv. Comput.2
2015 Hardware-Assisted Secure Resource Accounting under a Vulnerable Hypervisor
abstract
With the proliferation of cloud computing to outsource computation in remote servers, the accountability of computational resources has emerged as an important new challenge for both cloud users and providers. Among the cloud resources, CPU and memory are difficult to verify their actual allocation, since the current virtualization techniques attempt to hide the discrepancy between physical and virtual allocations for the two resources. This paper proposes an online verifiable resource accounting technique for CPU and memory allocation for cloud computing. Unlike prior approaches for cloud resource accounting, the proposed accounting mechanism, called Hardware-assisted Resource Accounting (HRA), uses the hardware support for system management mode (SMM) and virtualization to provide secure resource accounting, even if the hypervisor is compromised. Using a secure isolated execution support of SMM, this study investigates two aspects of verifiable resource accounting for cloud systems. First, this paper presents how the hardware-assisted SMM and virtualization techniques can be used to implement the secure resource accounting mechanism even under a compromised hypervisor. Second, the paper investigates a sample-based resource accounting technique to minimize performance overheads. Using a statistical random sampling method, the technique estimates the overall CPU and memory allocation status with 99%~100% accuracies and performance degradations of 0.1%~0.5%.
Seongwook Jin, Jinho Seol, Jaehyuk Huh 0001, Seung Ryoul Maeng
VEE1
2015 Fast Two-Level Address Translation for Virtualized Systems
abstract
Recently, there have been several improvements in architectural supports for two-level address translation for virtualized systems. However, those improvements including HW-based two-dimensional (2D) page walkers have extended the traditional multi-level page tables, without considering the memory management characteristics of virtual machines. This paper exploits the unique behaviors of the hypervisor, and proposes three new nested address translation schemes for virtualized systems. The first scheme called nested segmentation is designed for static memory allocation, and uses HW segmentation to map the VM memory directly to large contiguous memory regions. The second scheme proposes to use a flat nested page table for each VM, reducing memory accesses by the current 2D page walkers. The third scheme uses speculative inverted shadow paging, backed by non-speculative flat nested page tables. The speculative mechanism provides direct translation with a single memory reference for common cases without page table synchronization overheads. We evaluate the proposed schemes with the Xen hypervisor running on a full system simulator. Nested segmentation can reduce the overheads of two-level translation significantly for a certain cloud computing model. The nested segmentation, flat page tables, and speculative shadowing improve a state-of-the-art 2D page walker by 10, 7, and 14 percent respectively.
Jeongseob Ahn, Seongwook Jin, Jaehyuk Huh 0001
IEEE Trans. Computers2
2015 H-SVM: Hardware-Assisted Secure Virtual Machines under a Vulnerable Hypervisor
abstract
With increasing demands on cloud computing, protecting guest virtual machines (VMs) from malicious attackers has become critical to provide secure services. The current cloud security model with software-based virtualization relies on the invulnerability of the software hypervisor and its trustworthy administrator with the root permission. However, compromising the hypervisor with remote attacks or root permission grants the attackers with a full access capability to the memory and context of a guest VM. This paper proposes a HW-based approach to protect guest VMs even under an untrusted hypervisor. With the proposed mechanism, memory isolation is provided by the secure hardware, which is much less vulnerable than the software hypervisor. The proposed mechanism extends the current hardware support for memory virtualization based on nested paging with a small extra hardware cost. The hypervisor can still flexibly allocate physical memory pages to virtual machines for efficient resource management. In addition to the system design for secure virtualization, this paper presents a prototype implementation using system management mode. Although the current system management mode is not intended for security functions and thus limits the performance and complete protection, the prototype implementation proves the feasibility of the proposed design.
Seongwook Jin, Jeongseob Ahn, Jinho Seol, Sanghoon Cha, Jaehyuk Huh 0001, Seung Ryoul Maeng
IEEE Trans. Computers1
2013 Towards Assurance of Availability in Virtualized Cloud System
abstract
Cloud computing naturally shares physical resources, which is provided by virtualization technology. In contrast to the strength of virtualization, the serious security concerns raises due to the complexity of virtualization. It will place obstacles on the road to spread of cloud computing. In order to resolve the concern, many researchers focus on guaranteeing confidentiality and integrity of virtual machines except availability. We can support SLA (Service Level Agreement) as a part of assuring availability of virtual machines by SMM (System Management Mode)- based mechanism. Even if hypervisor is compromised, the mechanism can detect violations of SLA in virtualized cloud system.
Seongwook Jin, Jinho Seol, Seung Ryoul Maeng
CCGRID1
2013 Secure Storage Service for IaaS Cloud Users
abstract
Cloud computing enables to reduce operating costs and maximize resource utilization. However, current cloud infrastructure is insufficient to guarantee the confidentiality of classified information for cloud users because one of administrators with privilege or remote hackers compromising management tools can leak the information. This paper addresses storage issues in cloud computing and proposes a secure storage service where stored user data are protected even against a malicious administrator and compromised software. We describe the architecture of proposed design and discuss the security issues of the design.
Jinho Seol, Seongwook Jin, Seung Ryoul Maeng
CCGRID2
2012 Revisiting hardware-assisted page walks for virtualized systems
abstract
Recent improvements in architectural supports for virtualization have extended traditional hardware page walkers to traverse nested page tables. However, current two-dimensional (2D) page walkers have been designed under the assumption that the usage patterns of guest and nested page tables are similar. In this paper, we revisit the architectural supports for nested page table walks to incorporate the unique characteristics of memory management by hypervisors. Unlike page tables in native systems, nested page table sizes do not impose significant overheads on the overall memory usage. Based on this observation, we propose to use flat nested page tables to reduce unnecessary memory references for nested walks. A competing mechanism to HW 2D page walkers is shadow paging, which duplicates guest page tables but provides direct translations from guest virtual to system physical addresses. However, shadow paging has been suffering from the overheads of synchronization between guest and shadow page tables. The second mechanism we propose is a speculative shadow paging mechanism, called speculative inverted shadow paging, which is backed by non-speculative flat nested page tables. The speculative mechanism provides a direct translation with a single memory reference for common cases, and eliminates the page table synchronization overheads. We evaluate the proposed schemes with the real Xen hypervisor running on a full system simulator. The flat page tables improve a state-of-the-art 2D page walker with a page walk cache and nested TLB by 7%. The speculative shadow paging improves the same 2D page walker by 14%.
Jeongseob Ahn, Seongwook Jin, Jaehyuk Huh 0001
ISCA2
2011 Architectural support for secure virtualization under a vulnerable hypervisor
abstract
Although cloud computing has emerged as a promising future computing model, security concerns due to malicious tenants have been deterring its fast adoption. In cloud computing, multiple tenants may share physical systems by using virtualization techniques. In such a virtualized system, a software hypervisor creates virtual machines (VMs) from the physical system, and provides each user with an isolated VM. However, the hypervisor, with a full control over hardware resources, can access the memory pages of guest VMs without any restriction. By compromising the hypervisor, a malicious user can access the memory contents of the VMs used by other users.
Seongwook Jin, Jeongseob Ahn, Sanghoon Cha, Jaehyuk Huh 0001
MICRO1
2010 HAMA: An Efficient Matrix Computation with the MapReduce Framework
abstract
Various scientific computations have become so complex, and thus computation tools play an important role. In this paper, we explore the state-of-the-art framework providing high-level matrix computation primitives with MapReduce through the case study approach, and demonstrate these primitives with different computation engines to show the performance and scalability. We believe the opportunity for using MapReduce in scientific computation is even more promising than the success to date in the parallel systems literature.
Sangwon Seo, Edward J. Yoon, Jaehong Kim 0006, Seongwook Jin, Jin-Soo Kim 0001, Seung Ryoul Maeng
CloudCom4