WAVEN: WebAssembly Memory Virtualization for Enclaves
Weili Wang, Honghan Ji, Peixuan He, Yao Zhang, Ye Wu, Yinqian Zhang
Abstract
—The advancement of trusted execution environments (TEEs) has enabled the confidential computing paradigm and created new application scenarios for WebAssembly (Wasm). “Wasm+TEE” designs achieve in-enclave multi-tenancy with strong isolation, facilitating concurrent execution of untrusted code instances from multiple users. However, the linear memory model of Wasm lacks efficient cross-module data sharing and fine-grained memory access control, significantly restricting its applications in certain confidential computing scenarios where secure data sharing is essential ( e.g. , confidential stateful FaaS and data marketplaces). In this paper, we propose W AVEN (WebAssembly Memory Virtualization for ENclaves), a novel WebAssembly memory virtualization scheme, to enable memory sharing among Wasm modules and page-level access control. We implement W AVEN atop WAMR, a popular Wasm runtime for TEEs, and empirically demonstrate its efficiency and effectiveness. To the best of our knowledge, our work represents the first approach that enables cross-module memory sharing with fine-grained memory access control in Wasm.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6136f0cc-678e-44b0-8976-dd8ef2c7e8c7Cited by top-tier papers1
Ask how each one uses itBuilds on20
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- Faasm: Lightweight Isolation for Efficient Stateful Serverless ComputingSimon Shillaker, Peter R. PietzuchUSENIX ATC 2020 · 382 citations
- SANCTUARY: ARMing TrustZone with User-space EnclavesFerdinand Brasser, David Gens, Patrick Jauernig, Ahmad-Reza Sadeghi et al.NDSS 2019 · 191 citations
- CURE: A Security Architecture with CUstomizable and Resilient EnclavesRaad Bahmani, Ferdinand Brasser, Ghada Dessouky, Patrick Jauernig et al.USENIX Security 2021 · 150 citations
- Occlum: Secure and Efficient Multitasking Inside a Single Enclave of Intel SGXYouren Shen, Hongliang Tian, Yu Chen, Kang Chen et al.ASPLOS 2020 · 144 citations
Related papers
- On (the Lack of) Code Confidentiality in Trusted Execution EnvironmentsIvan Puddu, Moritz Schneider, Daniele Lain, Stefano Boschetto et al.S&P 2024 · 14 citations
- WaVe: a verifiably secure WebAssembly sandboxing runtimeEvan Johnson, Evan Laufer, Zijie Zhao, Dan Gohman et al.S&P 2023
- Exploring and Exploiting the Resource Isolation Attack Surface of WebAssembly ContainersZhaofeng Yu, Dongyang Zhan, Lin Ye, Haining Yu et al.USENIX Security 2025
- Reusable Enclaves for Confidential Serverless ComputingShixuan Zhao, Pinshen Xu, Guoxing Chen, Mengya Zhang et al.USENIX Security 2023
- ZION: A Practical Confidential Virtual Machine Architecture on Commodity RISC-V ProcessorsJie Wang, Juan Wang, Yinqian ZhangDAC 2025 · 3 citations
