USENIX Security2020Top-tier venue
Civet: An Efficient Java Partitioning Framework for Hardware Enclaves
Chia-Che Tsai, Jeongseok Son, Bhushan Jain, John McAvey, Raluca Ada Popa, Donald E. Porter
Abstract
Hardware enclaves are designed to execute small pieces of sensitive code or to operate on sensitive data, in isolation from larger, less trusted systems. Partitioning a large, legacy application requires significant effort. Partitioning an application written in a managed language, such as Java, is more challenging because of mutable language characteristics, extensive code reachability in class libraries, and the inevitability of using a heavyweight runtime. Civet is a framework for partitioning Java applications into enclaves. Civet reduces the number of lines of code in the enclave and uses language-level defenses, including deep type checks and dynamic taint-tracking, to harden the enclave interface. Civet also contributes a partitioned Java runtime design, including a garbage collection design optimized for the peculiarities of enclaves. Civet is efficient for data-intensive workloads; partitioning a Hadoop mapper reduces the enclave overhead from 10× to 16-22% without taint-tracking or 70-80% with taint-tracking. HDFS Yarn Scheduler Thread Commodity JVM MapTask(s) ReduceTask(s) map(K,V,Context) reduce(K,V[],Context) JNI Standard Classes Direct Invocation Enclave Protection Thread Thread Thread Thread Thread (a) Non-partitioned model needs to run the entire Hadoop framework in an enclave. HDFS Yarn Scheduler Thread Commodity JVM MapTask(s) ReduceTask(s) JNI Standard Classes Partitioned JVM Enclave Invocation Direct Invocation Enclave Protection Thread Thread Thread Thread Thread map(K,V,Context) reduce(K,V[],Context)
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 60d4a485-0721-4ccd-8329-9518fe885f2aCited by top-tier papers13
- Scalable Memory Protection in the PENGLAI EnclaveErhu Feng, Xu Lu, Dong Du, Bicheng Yang et al.OSDI 2021 · 126 citations
- Twine: An Embedded Trusted Runtime for WebAssemblyJämes Ménétrey, Marcelo Pasin, Pascal Felber, Valerio SchiavoniICDE 2021 · 58 citations
- CubicleOS: a library OS with software componentisation for practical isolationVasily A. Sartakov, Lluís Vilanova, Peter R. PietzuchASPLOS 2021 · 38 citations
- Nested Enclave: Supporting Fine-grained Hierarchical Isolation with SGXJoongun Park, Naegyeong Kang, Taehoon Kim, Youngjin Kwon et al.ISCA 2020 · 33 citations
- HyperEnclave: An Open and Cross-platform Trusted Execution EnvironmentYuekai Jia, Shuang Liu, Wenhao Wang, Yu Chen et al.USENIX ATC 2022 · 24 citations
Builds on7
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim et al.USENIX Security 2017 · 536 citations
- Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGXWenhao Wang, Guoxing Chen, Xiaorui Pan, Yinqian Zhang et al.CCS 2017 · 403 citations
- Telling Your Secrets without Page Faults: Stealthy Page Table-Based Attacks on Enclaved ExecutionJo Van Bulck, Nico Weichbrodt, Rüdiger Kapitza, Frank Piessens et al.USENIX Security 2017 · 316 citations
Related papers
- Weave: Efficient and Expressive Oblivious Analytics at ScaleMahdi Soleimani, Grace Jia, Anurag KhandelwalOSDI 2025 · 1 citation
- Lejacon: A Lightweight and Efficient Approach to Java Confidential Computing on SGXXinyuan Miao, Ziyi Lin, Shaojun Wang, Lei Yu et al.ICSE 2023 · 1 citation
- MULCOTAINT: Towards Efficient Multi-tag Dynamic Taint Analysis via Hardware/Software Co-designBing Qi, Yi Yang, Xiangkun Jia, Zhengpin Qian et al.USENIX Security 2026
- Isolating functions at the hardware limit with virtinesNicholas C. Wanninger, Joshua J. Bowden, Kirtankumar Shetty, Ayush Garg et al.EuroSys 2022 · 17 citations
- VirTEE: a full backward-compatible TEE with native live migration and secure I/OJianqiang Wang, Pouya Mahmoody, Ferdinand Brasser, Patrick Jauernig et al.DAC 2022 · 11 citations
