Hazel: Secure and Efficient Disaggregated Storage
Marcin Chrapek, Meni Orenbach, Ahmad Atamli, Marcin Copik, Mikhail Khalilov, Fritz Alder, Torsten Hoefler

TL;DR
Hazel is a novel storage management system that enhances disaggregated NVMe-oF storage with strong security guarantees and high performance, utilizing innovative control and data path optimizations including counter-leasing and a new Merkle Tree structure.
Contribution
Hazel extends NVMe-oF with a security-aware control plane and optimized data path, introducing counter-leasing and a disaggregated Merkle Tree for secure, efficient storage management.
Findings
Achieves 1-2% performance degradation in various workloads
Provides strong confidentiality, integrity, and freshness guarantees
Supports offloading to CC-capable smart NICs
Abstract
Disaggregated storage with NVMe-over-Fabrics (NVMe-oF) has emerged as the standard solution in modern supercomputers and data center clusters, achieving superior performance, resource utilization, and power efficiency. Simultaneously, confidential computing (CC) is becoming the de facto security paradigm, enforcing stronger isolation and protection for sensitive workloads. However, securing state-of-the-art storage with traditional CC methods struggles to scale and compromises performance or security. To address these issues, we introduce Hazel, a storage management system that extends the NVMe-oF protocol capabilities and adheres to the CC threat model, providing confidentiality, integrity, and freshness guarantees. Hazel offers an appropriate control path with novel concepts such as counter-leasing. Hazel also optimizes data path performance by leveraging NVMe metadata and introducing…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Data Storage Technologies · Cloud Data Security Solutions · Security and Verification in Computing
