{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:43:45Z","timestamp":1750308225463,"version":"3.41.0"},"reference-count":12,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2005,3,1]],"date-time":"2005-03-01T00:00:00Z","timestamp":1109635200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGARCH Comput. Archit. News"],"published-print":{"date-parts":[[2005,3]]},"abstract":"<jats:p>\n            Separation of control and data plane is a principle increasingly used to improve the performance of network protocols and applications, such as the Web. Use of security mechanisms, such as the SSL\/TLS protocol, can negate these performance gains, since such mechanisms need to be located on the data path. We argue that the same principle of separation can be applied to security mechanisms, by removing the web server from the secure data path.We present a\n            <jats:italic>minimal<\/jats:italic>\n            operating system extension that can improve the performance of web servers using SSL\/TLS by up to 27%. Our intuition is that protocol framing and cryptographic transforms can be applied to incoming and outgoing data frames by the operating system under a policy specified by the web server. In this way, we can reduce the number of system calls and context switches to a small constant number, and the amount of data copying that involves the web server by 100%. We describe our prototype implementation for the OpenBSD operating system and quantify its performance implications.\n          <\/jats:p>","DOI":"10.1145\/1055626.1055635","type":"journal-article","created":{"date-parts":[[2005,11,7]],"date-time":"2005-11-07T19:28:32Z","timestamp":1131391712000},"page":"58-64","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["The case for crypto protocol awareness inside the OS kernel"],"prefix":"10.1145","volume":"33","author":[{"given":"Matthew","family":"Burnside","sequence":"first","affiliation":[{"name":"Columbia University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Angelos D.","family":"Keromytis","sequence":"additional","affiliation":[{"name":"Columbia University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2005,3]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.1999.751458"},{"key":"e_1_2_1_2_1","volume-title":"Proceedings of the RSA Conference","author":"Boneh D.","year":"2001","unstructured":"D. Boneh and N. Shacham . Improving SSL Hand--shake Performance via Batching . In Proceedings of the RSA Conference , January 2001 . D. Boneh and N. Shacham. Improving SSL Hand--shake Performance via Batching. In Proceedings of the RSA Conference, January 2001."},{"key":"e_1_2_1_3_1","first-page":"367","volume-title":"Proceedings of CRYPTO","author":"Broscius A. G.","year":"1991","unstructured":"A. G. Broscius and J. M. Smith . Exploiting Parallelism in Hardware Implementation of the DES . In Proceedings of CRYPTO , pages 367 -- 376 , August 1991 . A. G. Broscius and J. M. Smith. Exploiting Parallelism in Hardware Implementation of the DES. In Proceedings of CRYPTO, pages 367--376, August 1991."},{"key":"e_1_2_1_4_1","volume-title":"Proceedings of the Network and Distributed Systems Security Symposium (NDSS)","author":"Coarfa C.","year":"2002","unstructured":"C. Coarfa , P. Druschel , and D. Wallach . Performance Analysis of TLS Web Servers . In Proceedings of the Network and Distributed Systems Security Symposium (NDSS) , February 2002 . C. Coarfa, P. Druschel, and D. Wallach. Performance Analysis of TLS Web Servers. In Proceedings of the Network and Distributed Systems Security Symposium (NDSS), February 2002."},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/65.224051"},{"key":"e_1_2_1_6_1","volume-title":"Secure Web Server Performance Dramatically Improved By Caching SSL Session Keys. In Workshop on Internet Server Performance, held in conjunction with SIGMETRICS","author":"Goldberg A.","year":"1998","unstructured":"A. Goldberg , R. Buff , and A. Schmitt . Secure Web Server Performance Dramatically Improved By Caching SSL Session Keys. In Workshop on Internet Server Performance, held in conjunction with SIGMETRICS , June 1998 . A. Goldberg, R. Buff, and A. Schmitt. Secure Web Server Performance Dramatically Improved By Caching SSL Session Keys. In Workshop on Internet Server Performance, held in conjunction with SIGMETRICS, June 1998."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/166237.166262"},{"key":"e_1_2_1_8_1","volume-title":"Raadt. The Design of the OpenBSD Cryptographic Framework. In Proceedings of the USENIX Technical Conference","author":"Keromytis A. D.","year":"2003","unstructured":"A. D. Keromytis , J. L. Wright , and T. de Raadt. The Design of the OpenBSD Cryptographic Framework. In Proceedings of the USENIX Technical Conference , June 2003 . A. D. Keromytis, J. L. Wright, and T. de Raadt. The Design of the OpenBSD Cryptographic Framework. In Proceedings of the USENIX Technical Conference, June 2003."},{"key":"e_1_2_1_9_1","first-page":"41","volume-title":"Proceedings of the USENIX Annual Technical Conference, Freenix Track","author":"Miltchev S.","year":"2002","unstructured":"S. Miltchev , S. Ioannidis , and A. D. Keromytis . A Study of the Relative Costs of Network Security Protocols . In Proceedings of the USENIX Annual Technical Conference, Freenix Track , pages 41 -- 48 , June 2002 . S. Miltchev, S. Ioannidis, and A. D. Keromytis. A Study of the Relative Costs of Network Security Protocols. In Proceedings of the USENIX Annual Technical Conference, Freenix Track, pages 41--48, June 2002."},{"key":"e_1_2_1_10_1","volume-title":"The Synthesis System. Computing Systems, 1(1)","author":"Pu C.","year":"1988","unstructured":"C. Pu , H. Massalin , J. Ioannidis , and P. Metzger . The Synthesis System. Computing Systems, 1(1) , 1988 . C. Pu, H. Massalin, J. Ioannidis, and P. Metzger. The Synthesis System. Computing Systems, 1(1), 1988."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/65.224055"},{"key":"e_1_2_1_12_1","first-page":"229","volume-title":"Proceedings of INET","author":"Smith J. M.","year":"1992","unstructured":"J. M. Smith , C. B. S. Traw , and D. J. Farber . Cryptographic Support for a Gigabit Network . In Proceedings of INET , pages 229 -- 237 , June 1992 . J. M. Smith, C. B. S. Traw, and D. J. Farber. Cryptographic Support for a Gigabit Network. In Proceedings of INET, pages 229--237, June 1992."}],"container-title":["ACM SIGARCH Computer Architecture News"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1055626.1055635","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1055626.1055635","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T16:31:27Z","timestamp":1750264287000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1055626.1055635"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005,3]]},"references-count":12,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2005,3]]}},"alternative-id":["10.1145\/1055626.1055635"],"URL":"https:\/\/doi.org\/10.1145\/1055626.1055635","relation":{},"ISSN":["0163-5964"],"issn-type":[{"type":"print","value":"0163-5964"}],"subject":[],"published":{"date-parts":[[2005,3]]},"assertion":[{"value":"2005-03-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}