An Extensible Orchestration and Protection Framework for Confidential Cloud Computing
Adil Ahmad, Alex Schultz, Byoungyoung Lee, Pedro Fonseca
Abstract
Confidential computing solutions are crucial to address the cloud privacy concerns. Although SGX has witnessed significant adoption in the cloud, the reliance on hardware implementation is restrictive for cloud providers in terms of orchestrating deployments and providing stronger security to their clients' enclaves. eOPF addresses this limitation by providing a comprehensive, secure hypervisor-level instrumentation framework with the ability to monitor all enclave-OS interactions and implement protected services. eOPF overcomes several challenges including bridging the semantic gap between the hypervisor and SGX and attesting the co-location of the framework with enclaves. Using eOPF, we implement two protected services that provide platform resource orchestration and complementary enclave side-channel defense. Our evaluation shows that eOPF incurs very low performance overhead (<2%) in its default state and only modest overhead (geometric mean of 17% on SPEC) when strong, complementary side-channel defenses are enabled, making eOPF an efficient and practical solution for the cloud.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9bd89f92-c915-4c6a-ae53-69b7825cc499Cited by top-tier papers8
- Veil: A Protected Services Framework for Confidential Virtual MachinesAdil Ahmad, Botong Ou, Congyu Liu, Xiaokuan Zhang et al.ASPLOS 2023 · 12 citations
- Pegasus: Transparent and Unified Kernel-Bypass Networking for Fast Local and Remote CommunicationDinglan Peng, Congyu Liu, Tapti Palit, Anjo Vahldiek-Oberwagner et al.EuroSys 2025 · 6 citations
- The HitchHiker's Guide to High-Assurance System Observability Protection with Efficient Permission SwitchesChuqi Zhang, Jun Zeng, Yiming Zhang, Adil Ahmad et al.CCS 2024 · 4 citations
- Kaleidoscope: Precise Invariant-Guided Pointer AnalysisTapti Palit, Pedro FonsecaASPLOS 2024 · 3 citations
- AEX-NStep: Probabilistic Interrupt Counting Attacks on Intel SGXNicolas Dutly, Friederike Groschupp, Ivan Puddu, Kari Kostiainen et al.S&P 2026 · 1 citation
Builds on25
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim et al.USENIX Security 2017 · 536 citations
- T-SGX: Eradicating Controlled-Channel Attacks Against Enclave ProgramsMing-Wei Shih, Sangho Lee, Taesoo Kim, Marcus PeinadoNDSS 2017 · 431 citations
Related papers
- Autarky: closing controlled channels with self-paging enclavesMeni Orenbach, Andrew Baumann, Mark SilbersteinEuroSys 2020 · 29 citations
- OPERA: Open Remote Attestation for Intel's Secure EnclavesGuoxing Chen, Yinqian Zhang, Ten-Hwang LaiCCS 2019 · 67 citations
- Confidential Serverless Made Efficient with Plug-In EnclavesMingyu Li, Yubin Xia, Haibo ChenISCA 2021 · 32 citations
- Klotski: Efficient Obfuscated Execution against Controlled-Channel AttacksPan Zhang, Chengyu Song, Heng Yin, Deqing Zou et al.ASPLOS 2020 · 14 citations
- HyperEnclave: An Open and Cross-platform Trusted Execution EnvironmentYuekai Jia, Shuang Liu, Wenhao Wang, Yu Chen et al.USENIX ATC 2022 · 24 citations
