Gramine-TDX: A Lightweight OS Kernel for Confidential VMs
Dmitrii Kuvaiskii, Dimitrios Stavrakakis, Kailun Qin, Cedric Xing, Pramod Bhatotia, Mona Vij
Abstract
While Confidential Virtual Machines (CVMs) have emerged as a prominent way for hardware-assisted confidential computing, their primary usage is not suitable for small, specialized, security-critical workloads, i.e., legacy VMs with their conventional OS distributions result in a large trusted computing base. In this paper, we present the Gramine-TDX OS kernel to execute slim, single-purpose, security-first, unmodified Linux workloads with a minimal attack surface. In comparison to a typical Linux kernel, Gramine-TDX's codebase is ∼ 50× less in binary size and has a significantly smaller attack surface, which makes it a perfect match for emerging cloud-native confidential-computing workloads. Our evaluation on 11 workloads indicates that Gramine-TDX has 1-25% average overhead for CPU-and memory-intensive applications. Performance on network-and FS-intensive applications can drop to 6% of the native application's, as Gramine-TDX prioritizes security over optimizations in virtual hardware communication. We build our prototype using Intel®Trust Domain Extensions (TDX). CCS CONCEPTS • Security and privacy → Systems security; Trusted computing; • Software and its engineering → Operating systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 25a3b0bc-fe42-4705-a4e8-7e00563a019dCited by top-tier papers8
- Trusting What You Cannot See: Auditable Fine-Tuning and Inference for Proprietary AIHeng Jin, Chaoyu Zhang, Hexuan Yu, Shanghao Shi et al.USENIX Security 2026 · 4 citations
- Erebor: A Drop-In Sandbox Solution for Private Data Processing in Untrusted Confidential Virtual MachinesChuqi Zhang, Rahul Priolkar, Yuancheng Jiang, Yuan Xiao et al.EuroSys 2025 · 4 citations
- SACK: Shielding Dynamic Attribute-based Access Control in Persistent Key-Value StoresYanjing Ren, Jingwei Li, Patrick LeeVLDB 2026
- You Shall Not Pass into Ring-0! A User Privacy-Friendly Anti-Cheat Architecture for Personal ComputersSantosh Gokul Narayanan, Giovanni Paladino, Chuqi Zhang, Sangho Lee et al.CCS 2026
- Wallet: Confidential Serverless ComputingPatrick Sabanic, Masanori Misono, Teofil Bodea, Julian Pritzi et al.NSDI 2026
Builds on22
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic et al.EuroSys 2020 · 381 citations
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel et al.USENIX Security 2017 · 324 citations
- ROTE: Rollback Protection for Trusted ExecutionSinisa Matetic, Mansoor Ahmed, Kari Kostiainen, Aritra Dhar et al.USENIX Security 2017 · 249 citations
- OBLIVIATE: A Data Oblivious Filesystem for Intel SGXAdil Ahmad, Kyungtae Kim, Muhammad Ihsanulhaq Sarfaraz, Byoungyoung LeeNDSS 2018 · 144 citations
- Occlum: Secure and Efficient Multitasking Inside a Single Enclave of Intel SGXYouren Shen, Hongliang Tian, Yu Chen, Kang Chen et al.ASPLOS 2020 · 144 citations
Related papers
- Serverless Functions Made Confidential and Efficient with Split ContainersJiacheng Shi, Jinyu Gu, Yubin Xia, Haibo ChenUSENIX Security 2025
- WorksetEnclave: Towards Optimizing Cold Starts in Confidential Serverless with Workset-Based Enclave RestoreXiaolong Yan, Qihang Zhou, Zisen Wan, Feifan Qian et al.ASPLOS 2026
- TETD: Trusted Execution in Trust DomainsZhanbo Wang, Jiaxin Zhan, Xuhua Ding, Fengwei Zhang et al.USENIX Security 2025
- INCOGNITOS: A Practical Unikernel Design for Full-System Obfuscation in Confidential Virtual MachinesKha Dinh Duy, Jaeyoon Kim, Hajeong Lim, Hojoon LeeS&P 2025
- Veil: A Protected Services Framework for Confidential Virtual MachinesAdil Ahmad, Botong Ou, Congyu Liu, Xiaokuan Zhang et al.ASPLOS 2023 · 12 citations
