Lune

CCS2024Top-tier venue

Gramine-TDX: A Lightweight OS Kernel for Confidential VMs

Dmitrii Kuvaiskii, Dimitrios Stavrakakis, Kailun Qin, Cedric Xing, Pramod Bhatotia, Mona Vij

2024Year
10Citations
8Top-tier citations

Abstract

While Confidential Virtual Machines (CVMs) have emerged as a prominent way for hardware-assisted confidential computing, their primary usage is not suitable for small, specialized, security-critical workloads, i.e., legacy VMs with their conventional OS distributions result in a large trusted computing base. In this paper, we present the Gramine-TDX OS kernel to execute slim, single-purpose, security-first, unmodified Linux workloads with a minimal attack surface. In comparison to a typical Linux kernel, Gramine-TDX's codebase is ∼ 50× less in binary size and has a significantly smaller attack surface, which makes it a perfect match for emerging cloud-native confidential-computing workloads. Our evaluation on 11 workloads indicates that Gramine-TDX has 1-25% average overhead for CPU-and memory-intensive applications. Performance on network-and FS-intensive applications can drop to 6% of the native application's, as Gramine-TDX prioritizes security over optimizations in virtual hardware communication. We build our prototype using Intel®Trust Domain Extensions (TDX). CCS CONCEPTS • Security and privacy → Systems security; Trusted computing; • Software and its engineering → Operating systems.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 25a3b0bc-fe42-4705-a4e8-7e00563a019d

Cited by top-tier papers8

Ask how each one uses it

Builds on22

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines