EPK: Scalable and Efficient Memory Protection Keys
Jinyu Gu, Hao Li, Wentai Li, Yubin Xia, Haibo Chen
Abstract
As a hardware mechanism for facilitating intra-process memory isolation, Intel Memory Protection Keys (MPK) has been leveraged to efficiently improve the isolation, security, or performance of the software. However, it can only support 16 isolated memory domains, which significantly limits its applicability in many scenarios.
In this paper, we present EPK which leverages off-theshelf virtualization hardware features to extend the number of available protection domains in MPK. To demonstrate the effectiveness of EPK, we apply it in three scenarios, including better memory isolation for server applications as well as Non-Volatile Memory (NVM) applications, and a fast Inter-Process Communication (IPC) mechanism for microkernels. The evaluation results show that EPK can scale to provide hundreds of isolated domains. It can outperform the stateof-the-art (libmpk) by up to two orders of magnitude and usually achieve 95% of the performance of the system with no memory isolation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9c465c24-424d-4091-a1ea-7a92a196c7ccCited by top-tier papers18
- Going beyond the Limits of SFI: Flexible and Secure Hardware-Assisted In-Process Isolation with HFIShravan Narayan, Tal Garfinkel, Mohammadkazem Taram, Joey Rudek et al.ASPLOS 2023 · 27 citations
- LemonNFV: Consolidating Heterogeneous Network Functions at Line SpeedHao Li, Yihan Dang, Guangda Sun, Guyue Liu et al.NSDI 2023 · 21 citations
- MOAT: Towards Safe BPF Kernel ExtensionHongyi Lu, Shuai Wang, Yechang Wu, Wanning He et al.USENIX Security 2024 · 18 citations
- ISA-Grid: Architecture of Fine-grained Privilege Control for Instructions and RegistersShulin Fan, Zhichao Hua, Yubin Xia, Haibo Chen et al.ISCA 2023 · 9 citations
- Endokernel: A Thread Safe Monitor for Lightweight Subprocess IsolationFangfei Yang, Bumjin Im, Weijie Huang, Kelly Kaoudis et al.USENIX Security 2024 · 8 citations
Builds on14
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler et al.USENIX Security 2019 · 247 citations
- xMP: Selective Memory Protection for Kernel and User SpaceSergej Proskurin, Marius Momeu, Seyedhamed Ghavamnia, Vasileios P. Kemerlis et al.S&P 2020 · 89 citations
- IMIX: In-Process Memory Isolation EXtensionTommaso Frassetto, Patrick Jauernig, Christopher Liebchen, Ahmad-Reza SadeghiUSENIX Security 2018 · 77 citations
- Enforcing Least Privilege Memory Views for Multithreaded ApplicationsTerry Ching-Hsiang Hsu, Kevin J. Hoffman, Patrick Eugster, Mathias PayerCCS 2016 · 71 citations
- Harmonizing Performance and Isolation in Microkernels with Efficient Intra-kernel Isolation and CommunicationJinyu Gu, Xinyue Wu, Wentai Li, Nian Liu et al.USENIX ATC 2020 · 51 citations
Related papers
- VDom: Fast and Unlimited Virtual Domains on Multiple ArchitecturesZiqi Yuan, Siyu Hong, Rui Chang, Yajin Zhou et al.ASPLOS 2023 · 19 citations
- Hardware-Based Domain Virtualization for Intra-Process Isolation of Persistent Memory ObjectsYuanchao Xu, Chencheng Ye, Yan Solihin, Xipeng ShenISCA 2020 · 24 citations
- SpecMPK: Efficient In-Process Isolation with Speculative and Secure Permission Update InstructionDebpratim Adak, Huiyang Zhou, Eric Rotenberg, Amro AwadHPCA 2025 · 3 citations
- Limitations and Opportunities of Modern Hardware Isolation MechanismsXiangdong Chen, Zhaofeng Li, Tirth Jain, Vikram Narayanan et al.USENIX ATC 2024 · 7 citations
- μSwitch: Fast Kernel Context Isolation with Implicit Context SwitchesDinglan Peng, Congyu Liu, Tapti Palit, Pedro Fonseca et al.S&P 2023
