Bifrost: Analysis and Optimization of Network I/O Tax in Confidential Virtual Machines
Dingji Li, Zeyu Mi, Chenhui Ji, Yifan Tan, Binyu Zang, Haibing Guan, Haibo Chen
Abstract
Existing confidential VMs (CVMs) experience notable network performance overhead compared to traditional VMs. We present the first thorough performance analysis of various network-intensive applications in CVMs and find that the CVM-IO tax, which mainly comprises the bounce buffer mechanism and the packet processing in CVMs, has a significant impact on network I/O performance. Specifically, the CVM-IO tax squeezes out virtual CPU (vCPU) resources of performance-critical application workloads and may occupy more than 50% of CPU cycles. To minimize the CVM-IO tax, this paper proposes Bifrost, a novel para-virtualized I/O design that 1) eliminates the I/O payload bouncing tax by removing redundant encryption and 2) reduces the packet processing tax via pre-receiver packet reassembly, while still ensuring the same level of security guarantees. We have implemented a Bifrost prototype with only minor modifications to the guest Linux kernel and the userspace network I/O backend. Evaluation results on both AMD and Intel servers demonstrate that Bifrost significantly improves the performance of I/Ointensive applications in CVMs, and even outperforms the traditional VM by up to 21.50%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 90a8e2e6-6c1f-4290-8fd2-fb1615c68476Cited by top-tier papers11
- CPC: Flexible, Secure, and Efficient CVM Maintenance with Confidential Procedure CallsJiahao Chen, Zeyu Mi, Yubin Xia, Haibing Guan et al.USENIX ATC 2024 · 11 citations
- sIOPMP: Scalable and Efficient I/O Protection for TEEsErhu Feng, Dahu Feng, Dong Du, Yubin Xia et al.ASPLOS 2024 · 10 citations
- Gramine-TDX: A Lightweight OS Kernel for Confidential VMsDmitrii Kuvaiskii, Dimitrios Stavrakakis, Kailun Qin, Cedric Xing et al.CCS 2024 · 10 citations
- PipeLLM: Fast and Confidential Large Language Model Services with Speculative Pipelined EncryptionYifan Tan, Cheng Tan, Zeyu Mi, Haibo ChenASPLOS 2025 · 10 citations
- ScalaCache: Scalable User-Space Page Cache Management with Software-Hardware CoordinationLi Peng, Yuda An, You Zhou, Chenxi Wang et al.USENIX ATC 2024 · 6 citations
Builds on7
- A Systematic Look at Ciphertext Side Channels on AMD SEV-SNPMengyuan Li, Luca Wilke, Jan Wichelmann, Thomas Eisenbarth et al.S&P 2022 · 87 citations
- The Demikernel Datapath OS Architecture for Microsecond-scale Datacenter SystemsIrene Zhang, Amanda Raybuck, Pratyush Patel, Kirk Olynyk et al.SOSP 2021 · 83 citations
- CrossLine: Breaking "Security-by-Crash" based Memory Isolation in AMD SEVMengyuan Li, Yinqian Zhang, Zhiqiang LinCCS 2021 · 41 citations
- TwinVisor: Hardware-isolated Confidential Virtual Machines for ARMDingji Li, Zeyu Mi, Yubin Xia, Binyu Zang et al.SOSP 2021 · 39 citations
- Confidential computing for OpenPOWERGuerney D. H. Hunt, Ramachandra Pai, Michael V. Le, Hani Jamjoom et al.EuroSys 2021 · 38 citations
Related papers
- Bifrost: Alibaba's Next-Generation VPC Network with High-Performance Multipath Reliable TransportZihao Fan, Xing Li, Ye Yang, Bo Jiang et al.NSDI 2026
- FastIOV: Fast Startup of Passthrough Network I/O Virtualization for Secure ContainersYunzhuo Liu, Junchen Guo, Bo Jiang, Yang Song et al.EuroSys 2025 · 5 citations
- Exit-Less, Isolated, and Shared Access for Virtual MachinesKenichi Yasukata, Hajime Tazaki, Pierre-Louis AublinASPLOS 2023 · 7 citations
- EXO: Accelerating Storage Paravirtualization with eBPFShi Qiu, Li Wang, Yiming ZhangSC 2024 · 2 citations
- CoINT2: A Heuristic Coordinator for Responsive Receive-Side Network I/O Virtualization in Overcommitment CloudXu Huan, Jian Li, Haibing GuanINFOCOM 2025 · 1 citation
