ORC: Increasing Cloud Memory Density via Object Reuse with Capabilities
Vasily A. Sartakov, Lluís Vilanova, Munir Geden, David M. Eyers, Takahiro Shinagawa, Peter R. Pietzuch
Abstract
Cloud environments host many tenants, and typically there is substantial overlap between the application binaries and libraries executed by tenants. Thus, memory de-duplication can increase memory density by allocating memory for shared binaries only once. Existing de-duplication approaches, however, either rely on a shared OS to de-deduplicate binary objects, which provides unacceptably weak isolation; or exploit hypervisor-based de-duplication at the level of memory pages, which is blind to the semantics of the objects to be shared.
We describe Object Reuse with Capabilities (ORC), which supports the fine-grained sharing of binary objects between tenants, while isolating tenants strongly through a small trusted computing base (TCB). ORC uses hardware support for memory capabilities to isolate tenants, which permits shared objects to be accessible to multiple tenants safely. Since ORC shares binary objects within a single address space through capabilities, it uses a new relocation type to create per-tenant state using thread-local storage when loading shared objects. ORC supports the loading of objects by an untrusted guest, outside of its TCB, only verifying the safety of the loaded data. Our experiments show that, compared to hypervisor-based de-deduplication, ORC achieves a higher memory density with a lower performance overhead.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 40ac4967-9e3b-4763-b962-71f7d3a5018fCited by top-tier papers1
Ask how each one uses itBuilds on3
- Unikraft: fast, specialized unikernels the easy waySimon Kuenzer, Vlad-Andrei Badoiu, Hugo Lefeuvre, Sharan Santhanam et al.EuroSys 2021 · 116 citations
- CubicleOS: a library OS with software componentisation for practical isolationVasily A. Sartakov, Lluís Vilanova, Peter R. PietzuchASPLOS 2021 · 38 citations
- CAP-VMs: Capability-Based Isolation and Sharing in the CloudVasily A. Sartakov, Lluís Vilanova, David M. Eyers, Takahiro Shinagawa et al.OSDI 2022 · 24 citations
Related papers
- Sharing is leaking: blocking transient-execution attacks with core-gapped confidential VMsCharly Castes, Andrew BaumannASPLOS 2024 · 2 citations
- MTTM: Dynamic Fast Memory Partitioning with Bandwidth Optimization for Multi-tenant CloudChangjun Lee, Sangjin Choi, Youngjin KwonEuroSys 2026 · 1 citation
- A Software Approach to Defeating Side Channels in Last-Level CachesZiqiao Zhou, Michael K. Reiter, Yinqian ZhangCCS 2016 · 155 citations
- Breaking Isolation: A New Perspective on Hypervisor Exploitation via Cross-Domain AttacksGaoning Pan, Yiming Tao, Qinying Wang, Chunming Wu et al.NDSS 2026
- Demeter: A Scalable and Elastic Tiered Memory Solution for Virtualized Cloud via Guest DelegationJunliang Hu, Zhisheng Hu, Chun-Feng Wu, Ming-Chang YangSOSP 2025 · 1 citation
