ZION: A Practical Confidential Virtual Machine Architecture on Commodity RISC-V Processors
Jie Wang, Juan Wang, Yinqian Zhang
Abstract
A b stra ct-Trusted E xecu tion E nvironm ents (T E E s) p rovide robust h ardw are-based iso la tio n to m itigate d ata b reaches and privacy risk s. C onfid en tial V irtu al M achines (con fid en tial V M s o r CVM s) extend th ese ca p a b ilities b y u sin g V M s a s th e ir ex ecu tion ab straction , o fferin g su p erior com p atib ility over p rocess-based TEEs lik e In tel SG X . T he risin g dem and for C onfid en tial VM s h as spurred in novation s from m ajor ch ip m anu factu rers, such as AM D SEV, In tel TD X , an d A rm C C A , an d th e ir in teg ra tio n in to lea d in g d o u d p latform s, in du ctin g AW S, A zu re, and G oogle C loud. O n th e R ISC -V p latform , how ever, ex istin g TEE arehitectu res rely on p ro cess-level ab straction s o r cu stom hardw are, lea d in g to lim ited com p atib ility and scalab ility. T h is p ap er p resen ts Zion, a con fid en tial V M architecture fo r com m odity R ISC -V hardw are th a t o p erates w ith ou t cu s tom exten sion s. Zion en su res secu rity, flexib ility, an d efficien cy through a sh ort-p ath C V M m ode an d a secu re vC P U m echanism fo r p rotectin g an d efficien tly u p d atin g vC PU sta te s, en h ancing co n text-sw itch in g p erform ance. I t com b ines P h ysical M em ory P rotection (PM P) w ith p agin g fo r scalab le m em ory iso la tio n , em p loys a h ierarch ical m em ory stru ctu re fo r efficien t m anage m en t, and in trod u ces a sp lit-p age-tab le-b ased m echanism for secu re m em ory sh arin g w ith v ir tió d evices. E valu ation s show Zion ach ieves u n d er 5% overhead in real-w orld ap p lica tio n s, d em onstratin g its p racticality.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a424933b-ed3e-45a4-921c-8a08a0dd63e0Builds on13
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic et al.EuroSys 2020 · 381 citations
- CURE: A Security Architecture with CUstomizable and Resilient EnclavesRaad Bahmani, Ferdinand Brasser, Ghada Dessouky, Patrick Jauernig et al.USENIX Security 2021 · 150 citations
- VoltPillager: Hardware-based fault injection attacks against Intel SGX Enclaves using the SVID voltage scaling interfaceZitai Chen, Georgios Vasilakis, Kit Murdock, Edward Dean et al.USENIX Security 2021 · 127 citations
Related papers
- vTZ: Virtualizing ARM TrustZoneZhichao Hua, Jinyu Gu, Yubin Xia, Haibo Chen et al.USENIX Security 2017 · 136 citations
- VirTEE: a full backward-compatible TEE with native live migration and secure I/OJianqiang Wang, Pouya Mahmoody, Ferdinand Brasser, Patrick Jauernig et al.DAC 2022 · 11 citations
- Confidential computing for OpenPOWERGuerney D. H. Hunt, Ramachandra Pai, Michael V. Le, Hani Jamjoom et al.EuroSys 2021 · 38 citations
- TETD: Trusted Execution in Trust DomainsZhanbo Wang, Jiaxin Zhan, Xuhua Ding, Fengwei Zhang et al.USENIX Security 2025
- vSGX: Virtualizing SGX Enclaves on AMD SEVShixuan Zhao, Mengyuan Li, Yinqian Zhang, Zhiqiang LinS&P 2022 · 32 citations
