Kha Dinh Duy

dblp:305/7328 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
5since 2021 · last 2025
0000-0002-6285-3506ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 PIM-ORAM: Towards Oblivious RAM Primitives in Commodity Processing-In-Memory
abstract
Oblivious RAM (ORAM) is theoretically proven to render memory access patterns of a computation completely uniform, mitigating memory side-channel attacks. However, it is accompanied by orders of magnitude slower memory access latency and, thus, is often impractical in many circumstances. On the other hand, Processing-In-Memory (PIM) has been advancing as a solution to accelerate memory-intensive work-loads and mitigate the memory wall problem. In this paper, we explore the new direction of in-DRAM oblivious RAM with a design named PIM-ORAM. We retrofit the currently available commodity PIM hardware to provide future direction for secure computation on PIM, and design PIM-ORAM. Our design proposes split-data ORAM, a parallelizable in-memory ORAM scheme that takes full advantage of the parallel computing power of the PIM while retaining the original security guarantee of ORAM and dealing with the constraints existing in the commodity PIM. We evaluate PIM-ORAM using the PIM -enabled testbed cloud to provide more realistic numerical values. The evaluation shows that PIM-ORAM alleviates the increase of memory bus usage and ORAM access latency when the ORAM capacity increases.
Byeongsu Woo, Kha Dinh Duy, Youngkwang Han, Brent ByungHoon Kang, Hojoon Lee 0001
ACSAC2
2025 INCOGNITOS: A Practical Unikernel Design for Full-System Obfuscation in Confidential Virtual Machines
abstract
Recent works have repeatedly proven the practicality of side-channel attacks in undermining the confidentiality guarantees of Trusted Execution Environments such as Intel SGX. Meanwhile, the trusted execution in the cloud is witnessing a trend shift towards confidential virtual machines (CVMs). Unfortunately, several side-channel attacks have survived the shift and are feasible even for CVMs, along with the new attacks discovered on the CVM architectures. Previous works have explored defensive measures for securing userspace enclaves (i.e., Intel SGX) against side-channel attacks. However, the design space for a CVM-based obfuscation execution engine is largely unexplored. This paper proposes a unikernel design named NCOGNITOS provide full-system obfuscation for CVM-based cloud workloads. INCOGNITOS fully embraces unikernel principles such as minimized TCB and direct hardware access to render full-system obfuscation feasible. INCOGNITOS retrofits two key OS components, the scheduler and memory management, to implement a novel adaptive obfuscation scheme. INCOGNITOS's scheduling is designed to be self-sovereign from the timer interrupts from the untrusted hypervisor with its synchronous tick delivery. This allows INCOGNITOS to reliably monitor the frequency of the hypervisor's possession of execution control (i.e., VMExits) and adjust the frequency of memory rerandomization performed by the paging subsystem, which transparently performs memory rerandomization through direct MMU access. The resulting INCOGNITOS design makes a case for a self-obfuscating unikernel as a secure CVM deployment strategy while further advancing the obfuscation technique compared to previous works. Evaluation results demonstrate INCOGNITOS'S resilience against CVM attacks and show that its adaptive obfuscation scheme enables practical performance for real-world programs.
Kha Dinh Duy, Hajeong Lim, Hojoon Lee 0001
SP1
2024 RustSan: Retrofitting AddressSanitizer for Efficient Sanitization of Rust
Kyuwon Cho, Jongyoon Kim, Kha Dinh Duy, Hajeong Lim, Hojoon Lee 0001
USENIX Security Symposium3
2023 Capacity: Cryptographically-Enforced In-Process Capabilities for Modern ARM Architectures
abstract
In-process compartmentalization and access control have been actively explored to provide in-place and efficient isolation of in-process security domains. Many works have proposed compartmentalization schemes that leverage hardware features, most notably using the new page-based memory isolation feature called Protection Keys for Userspace (PKU) on x86. Unfortunately, the modern ARM architecture does not have an equivalent feature. Instead, newer ARM architectures introduced Pointer Authentication (PA) and Memory Tagging Extension (MTE), adapting the reference validation model for memory safety and runtime exploit mitigation. We argue that those features have been underexplored in the context of compartmentalization and that they can be retrofitted to implement a capability-based in-process access control scheme.
Kha Dinh Duy, Kyuwon Cho, Taehyun Noh, Hojoon Lee 0001
CCS1
2023 SE-PIM: In-Memory Acceleration of Data-Intensive Confidential Computing
abstract
Demand for data-intensive workloads and confidential computing are the prominent research directions shaping the future of cloud computing. Computer architectures are evolving to accommodate the computing of large data. Meanwhile, a plethora of works has explored protecting the confidentiality of the in-cloud computation in the context of hardware-based secure enclaves. However, the approach has faced challenges in achieving efficient large data computation. In this paper, we present a novel design, calledse-pim, that retrofits Processing-In-Memory (PIM) as a data-intensive confidential computing accelerator. PIM-accelerated computation renders large data computation highly efficient by minimizing data movement. Based on our observation that moving computation closer to memory can achieve efficiency of computation and confidentiality of the processed information simultaneously, we study the advantages of confidential computinginsidememory. We construct our findings into a software-hardware co-design calledse-pim. Our design illustrates the advantages of PIM-based confidential computing acceleration. We study the challenges in adapting PIM in confidential computing and propose a set of imperative changes, as well as a programming model that can utilize them. Our evaluation showsse-pimcan provide a side-channel resistant secure computation offloading and run data-intensive applications with negligible performance overhead compared to the baseline PIM model.
Kha Dinh Duy, Hojoon Lee 0001
IEEE Trans. Cloud Comput.1