AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
Article Link
Collect
Submit Manuscript
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Perspective

DPU for Cybersecurity: Enabling Inline Defense and Self-Protection

State Key Laboratory of Processors, Institute of Computing Technology, Chinese Academy of Sciences, Beijing 100190, China
University of Chinese Academy of Sciences, Beijing 100049, China
YUSUR Technology Co., Ltd., Beijing 100094, China
Show Author Information

Abstract

As conventional CPU-based security architectures struggle to scale with ever-growing network bandwidths and increasingly sophisticated cyberattacks, the data processing unit (DPU), a specialized processor for datacenter infrastructure, has emerged as a transformative foundation for secure and high-performance computing. Unlike prior fragmented studies, this work proposes a comprehensive security framework for DPUs by systematically investigating the DPUs' dual role in cybersecurity, serving both as an active security enforcer and as a critical component that must itself be protected. First, the framework offloads security policies onto the DPU to enable line-rate packet inspection and hardware-accelerated security processing. Second, the framework re-architects the DPU itself to defend against physical and architectural attacks, acknowledging that the DPU also introduces a new attack surface. We validate these two design directions through two representative case studies, demonstrating the effectiveness and practicality of the proposed DPU security framework. Experimental results show that the proposed framework reduces remote direct memory access (RDMA) cache side-channel detection latency by up to 98.7% compared with the state-of-the-art, while enabling a trusted execution environment on field-programmable gate array (FPGA)-based DPUs with sub-100 ns overhead and less than 4% FPGA resource consumption.

Electronic Supplementary Material

Video
JCST-2510-16034-Video.mp4
Download File(s)
JCST-2510-16034-Highlights.pdf (559 KB)

References

【1】
【1】
 
 
Journal of Computer Science and Technology
Pages 114-127

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Li X-W, Liao Y-K, Yan G-H. DPU for Cybersecurity: Enabling Inline Defense and Self-Protection. Journal of Computer Science and Technology, 2026, 41(1): 114-127. https://doi.org/10.1007/s11390-026-6034-y

369

Views

0

Crossref

0

Web of Science

0

Scopus

0

CSCD

Received: 25 October 2025
Accepted: 05 January 2026
Published: 30 April 2026
© Institute of Computing Technology, Chinese Academy of Sciences 2026