rkt-io: a direct I/O stack for shielded execution
Jörg Thalheim, Harshavardhan Unnibhavi, Christian Priebe, Pramod Bhatotia, Peter R. Pietzuch
Abstract
The shielding of applications using trusted execution environments (TEEs) can provide strong security guarantees in untrusted cloud environments. When executing I/O operations, today's shielded execution frameworks, however, exhibit performance and security limitations: they assign resources to the I/O path inefficiently, perform redundant data copies, use untrusted host I/O stacks with security risks and performance overheads. This prevents TEEs from running modern I/O-intensive applications that require high-performance networking and storage.
We describe rkt-io (pronounced "rocket I/O"), a direct userspace network and storage I/O stack specifically designed for TEEs that combines high-performance, POSIX compatibility and security. rkt-io achieves high I/O performance by employing direct userspace I/O libraries (DPDK and SPDK) inside the TEE for kernel-bypass I/O. For efficiency, rkt-io polls for I/O events directly, by interacting with the hardware instead of relying on interrupts, and it avoids data copies by mapping DMA regions in the untrusted host memory. To maintain full Linux ABI compatibility, the userspace I/O libraries are integrated with userspace versions of the Linux VFS and network stacks inside the TEE. Since it omits the host OS from the I/O path, does not suffer from host interface/Iago attacks. Our evaluation with Intel SGX TEEs shows that rkt-io is 9× faster for networking and 7× faster for storage compared to host-(Scone) and LibOS-based (SGX-LKL) I/O approaches.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b3afed6c-2158-424d-b408-4e848cd5fde7Cited by top-tier papers15
- The Demikernel Datapath OS Architecture for Microsecond-scale Datacenter SystemsIrene Zhang, Amanda Raybuck, Pratyush Patel, Kirk Olynyk et al.SOSP 2021 · 83 citations
- Towards High-throughput and Low-latency Billion-scale Vector Search via CPU/GPU Collaborative Filtering and Re-rankingBing Tian, Haikun Liu, Yuhang Tang, Shihai Xiao et al.FAST 2025 · 49 citations
- Avocado: A Secure In-Memory Distributed Storage SystemMaurice Bailleu, Dimitra Giantsidi, Vasilis Gavrielatos, Do Le Quoc et al.USENIX ATC 2021 · 39 citations
- Dissecting BFT Consensus: In Trusted Components we Trust!Suyash Gupta, Sajjad Rahnama, Shubham Pandey, Natacha Crooks et al.EuroSys 2023 · 27 citations
- ENGRAFT: Enclave-guarded Raft on Byzantine Faulty NodesWeili Wang, Sen Deng, Jianyu Niu, Michael K. Reiter et al.CCS 2022 · 19 citations
Builds on8
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic et al.EuroSys 2020 · 381 citations
- Panoply: Low-TCB Linux Applications With SGX EnclavesShweta Shinde, Dat Le Tien, Shruti Tople, Prateek SaxenaNDSS 2017 · 274 citations
- Hacking in Darkness: Return-oriented Programming against Secure EnclavesJae-Hyuk Lee, Jin Soo Jang, Yeongjin Jang, Nohyun Kwak et al.USENIX Security 2017 · 191 citations
- OBLIVIATE: A Data Oblivious Filesystem for Intel SGXAdil Ahmad, Kyungtae Kim, Muhammad Ihsanulhaq Sarfaraz, Byoungyoung LeeNDSS 2018 · 144 citations
Related papers
- Rakis: Secure Fast I/O Primitives Across Trust Boundaries on Intel SGXMansour Alharthi, Fan Sang, Dmitrii Kuvaiskii, Mona Vij et al.EuroSys 2025 · 6 citations
- TCP ≈ RDMA: CPU-efficient Remote Storage Access with i10Jaehyun Hwang, Qizhe Cai, Ao Tang, Rachit AgarwalNSDI 2020 · 70 citations
- sIOPMP: Scalable and Efficient I/O Protection for TEEsErhu Feng, Dahu Feng, Dong Du, Yubin Xia et al.ASPLOS 2024 · 10 citations
- BypassD: Enabling fast userspace access to shared SSDsSujay Yadalam, Chloe Alverti, Vasileios Karakostas, Jayneel Gandhi et al.ASPLOS 2024 · 5 citations
- UIEE: Secure and Efficient User-space Isolated Execution Environment for Embedded TEE SystemsHuaiyu Yan, Zhen Ling, Xuandong Chen, Xinhui Shao et al.NDSS 2026 · 4 citations
