JANUS: Cross-World, Cooperative Nested Virtualization for Secure Containers
Jiangshan Lai, Hang Huang, Quan Xu, Zhen Ren, Wenlong Hou, Wei Guo, Jia Rao, Hui Lu, Weidong Han, Jiesheng Wu, Jiang Liu, Naixuan Guan
Abstract
Secure containers such as Kata Containers strengthen isolation by running each container inside a lightweight VM. On today's virtualized clouds, this creates an unavoidable form of nested virtualization with dominant cost in memory virtualization. Existing approaches entangle CPU virtualization and three-level page-table management across hypervisors, forcing frequent cross-world synchronization and producing severe overheads for mixed memory-access workloads.
We present JANUS, a cross-world, cooperative nested virtualization architecture that cleanly separates CPU and memory virtualization responsibilities. JANUS performs all guest world switches entirely within the guest hypervisor through a lightweight switcher mechanism, while delegating all memory translation to the host hypervisor. This separation removes the host from the critical path of CPU events and eliminates the intermediate shadow or nested page tables that burden existing designs. JANUS introduces several key techniques, including VMFUNC-based EPTP switching for trap-free transitions between guest and nested-guest address spaces; a shadow-root mechanism that protects world-switch integration while allowing direct updates to the nested guest's page tables; and in-guest virtualization exception handling that enables the guest hypervisor to resolve second-level faults with only a single lightweight host interaction. Evaluations demonstrate that JANUS delivers an average performance improvement of 144% over PVM and 28.6% over KVM-based nested virtualization for real-world applications, and imposes less than 5% overhead compared to native containers in production deployment. JANUS demonstrates that rethinking nested virtualization around cross-world cooperation yields strong isolation with near-native container performance.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on18
- RunD: A Lightweight Secure Container Runtime for High-density Deployment and High-concurrency Startup in Serverless ComputingZijun Li, Jiagan Cheng, Quan Chen, Eryu Guan et al.USENIX ATC 2022 · 106 citations
- Houdini's Escape: Breaking the Resource Rein of Linux Control GroupsXing Gao, Zhongshu Gu, Zhengfa Li, Hani Jamjoom et al.CCS 2019 · 62 citations
- BlackBox: A Container Security Monitor for Protecting Containers on Untrusted Operating SystemsAlexander Van't Hof, Jason NiehOSDI 2022 · 44 citations
- High-density Multi-tenant Bare-metal CloudXiantao Zhang, Xiao Zheng, Zhi Wang, Hang Yang et al.ASPLOS 2020 · 39 citations
- Optimizing Nested Virtualization Performance Using Direct Virtual HardwareJin Tack Lim, Jason NiehASPLOS 2020 · 34 citations
Related papers
- Accelerating Nested Virtualization with HyperTurtleOri Ben Zur, Jakob Krebs, Shai Aviram Bergman, Mark SilbersteinUSENIX ATC 2025 · 2 citations
- Translation Pass-Through for Near-Native Paging Performance in VMsShai Bergman, Mark Silberstein, Takahiro Shinagawa, Peter R. Pietzuch et al.USENIX ATC 2023 · 10 citations
- PVM: Efficient Shadow Paging for Deploying Secure Containers in Cloud-native EnvironmentHang Huang, Jiangshan Lai, Jia Rao, Hui Lu et al.SOSP 2023 · 4 citations
- SKernel: An Elastic and Efficient Secure Container System at Scale with a Split-Kernel ArchitectureXiaohu Chai, Keyang Hu, Jianfeng Tan, Tiwei Bie et al.EuroSys 2026 · 1 citation
- A Hardware-Software Co-Design for Efficient Secure ContainersJiacheng Shi, Yang Yu, Jinyu Gu, Yubin XiaEuroSys 2025
