Nested Enclave: Supporting Fine-grained Hierarchical Isolation with SGX
Joongun Park, Naegyeong Kang, Taehoon Kim, Youngjin Kwon, Jaehyuk Huh
Abstract
Although hardware-based trusted execution environments (TEEs) have evolved to provide strong isolation with efficient hardware supports, their current monolithic model poses challenges in representing common software structures with modules produced from potentially untrusted 3rd parties. For better mapping of such modular software designs to trusted execution environments, it is necessary to extend the current monolithic model to a hierarchical one, which provides multiple inner TEEs within a TEE. For such hierarchical compartmentalization within a TEE, this paper proposes a novel hierarchical TEE called nested enclave, which extends the enclave support from Intel SGX. Inspired by the multi-level security model, nested enclave provides multiple inner enclaves sharing the same outer enclave. Inner enclaves can access the context of the outer enclave, but they are protected from the outer enclave and non-enclave execution. Peer inner enclaves are isolated from each other while accessing the execution environment of the shared outer enclave. Both of the inner and outer enclaves are protected from vulnerable privileged software and physical attacks. Such fine-grained nested enclaves allow secure multitiered environments using software modules from untrusted 3rd parties. The security-sensitive modules run on the inner enclave with the higher security level, while the 3rd party modules on the outer enclave. It can be further extended to provide a separate inner module for each user to process privacy-sensitive data while sharing the same library with efficient hardwareprotected communication channels. This study investigates three case scenarios implemented with an emulated nested enclave support, proving the feasibility and security improvement of the nested enclave model.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 21911498-6c98-40fc-a9c0-c4d49db3fc17Cited by top-tier papers13
- ShEF: shielded enclaves for cloud FPGAsMark Zhao, Mingyu Gao, Christos KozyrakisASPLOS 2022 · 53 citations
- DarKnight: An Accelerated Framework for Privacy and Integrity Preserving Deep Learning Using Trusted HardwareHanieh Hashemi, Yongqin Wang, Murali AnnavaramMICRO 2021 · 51 citations
- Confidential Serverless Made Efficient with Plug-In EnclavesMingyu Li, Yubin Xia, Haibo ChenISCA 2021 · 32 citations
- Client-optimized algorithms and acceleration for encrypted compute offloadingMcKenzie van der Hagen, Brandon LuciaASPLOS 2022 · 18 citations
- Elasticlave: An Efficient Memory Model for EnclavesJason Zhijingcheng Yu, Shweta Shinde, Trevor E. Carlson, Prateek SaxenaUSENIX Security 2022
Builds on6
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- T-SGX: Eradicating Controlled-Channel Attacks Against Enclave ProgramsMing-Wei Shih, Sangho Lee, Taesoo Kim, Marcus PeinadoNDSS 2017 · 431 citations
- Panoply: Low-TCB Linux Applications With SGX EnclavesShweta Shinde, Dat Le Tien, Shruti Tople, Prateek SaxenaNDSS 2017 · 274 citations
- vTZ: Virtualizing ARM TrustZoneZhichao Hua, Jinyu Gu, Yubin Xia, Haibo Chen et al.USENIX Security 2017 · 136 citations
- FLEXDROID: Enforcing In-App Privilege Separation in AndroidJaebaek Seo, Daehyeok Kim, Donghyun Cho, Insik Shin et al.NDSS 2016 · 114 citations
Related papers
- The Road to Trust: Building Enclaves within Confidential VMsWenhao Wang, Linke Song, Benshan Mei, Shuang Liu et al.NDSS 2025
- COIN Attacks: On Insecurity of Enclave Untrusted Interfaces in SGXMustakimur Rahman Khandaker, Yueqiang Cheng, Zhi Wang, Tao WeiASPLOS 2020 · 46 citations
- vSGX: Virtualizing SGX Enclaves on AMD SEVShixuan Zhao, Mengyuan Li, Yinqian Zhang, Zhiqiang LinS&P 2022 · 32 citations
- HyperEnclave: An Open and Cross-platform Trusted Execution EnvironmentYuekai Jia, Shuang Liu, Wenhao Wang, Yu Chen et al.USENIX ATC 2022 · 24 citations
- HyperTEE: A Decoupled TEE Architecture with Secure Enclave ManagementYunkai Bai, Peinan Li, Yubiao Huang, Michael C. Huang et al.MICRO 2024 · 5 citations
