Sharing is leaking: blocking transient-execution attacks with core-gapped confidential VMs
Charly Castes, Andrew Baumann
Abstract
Confidential VMs on platforms such as Intel TDX, AMD SEV and Arm CCA promise greater security for cloud users against even a hypervisor-level attacker, but this promise has been shattered by repeated transient-execution vulnerabilities and CPU bugs. At the root of this problem lies the need to multiplex CPU cores with all their complex microarchitectural state among distrusting entities, with an untrusted hypervisor in control of the multiplexing.
We propose core-gapped confidential VMs, a set of softwareonly modifications that ensure that no distrusting code shares a core, thus removing all same-core side-channels and transient-execution vulnerabilities from the guest's TCB. We present an Arm-based prototype along with a performance evaluation showing that, not only does core-gapping offer performance competitive with non-confidential VMs, the greater locality achieved by avoiding shared cores can even improve performance for CPU-intensive workloads.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- IOValve: Leakage-Free I/O Sandbox for Large-Scale Untrusted Data ProcessingSangho Lee, Jules Drean, Yue Tan, Marcus PeinadoCCS 2025 · 1 citation
- Accelerating Confidential Databases with Crypto-Free MappingsWenxuan Huang, Zhanbo Wang, Mingyu LiOSDI 2026
Builds on35
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck et al.CCS 2019 · 464 citations
- RIDL: Rogue In-Flight Data LoadStephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo et al.S&P 2019 · 408 citations
Related papers
- Core slicing: closing the gap between leaky confidential VMs and bare-metal cloudZiqiao Zhou, Yizhou Shan, Weidong Cui, Xinyang Ge et al.OSDI 2023 · 12 citations
- TETD: Trusted Execution in Trust DomainsZhanbo Wang, Jiaxin Zhan, Xuhua Ding, Fengwei Zhang et al.USENIX Security 2025
- TwinVisor: Hardware-isolated Confidential Virtual Machines for ARMDingji Li, Zeyu Mi, Yubin Xia, Binyu Zang et al.SOSP 2021 · 39 citations
- CrossTalk: Speculative Data Leaks Across Cores Are RealHany Ragab, Alyssa Milburn, Kaveh Razavi, Herbert Bos et al.S&P 2021 · 162 citations
- CPC: Flexible, Secure, and Efficient CVM Maintenance with Confidential Procedure CallsJiahao Chen, Zeyu Mi, Yubin Xia, Haibing Guan et al.USENIX ATC 2024 · 11 citations
