Erebor: A Drop-In Sandbox Solution for Private Data Processing in Untrusted Confidential Virtual Machines
Chuqi Zhang, Rahul Priolkar, Yuancheng Jiang, Yuan Xiao, Mona Vij, Zhenkai Liang, Adil Ahmad
Abstract
Confidential virtual machines (CVMs) are designed to protect data in cloud machines, but they fail in this task in common Software-as-a-Service (SaaS) cloud environments. In such settings, the software stack within a CVM, including service programs and the operating system, that receives and processes data may intentionally disclose it to attackers. We present Erebor, a sandboxing architecture for CVMs that processes client data in secure containers, where restrictions apply to both (a) access by all untrusted outside components and (b) the sandbox's ability to communicate data through memory and software-controlled direct or covert exits. Erebor enables such restrictions through a security monitor design based on intra-kernel privilege isolation for CVM, fully compatible with emerging cloud deployments without requiring host modifications. Under realistic scenarios, such as large language model inference and private information retrieval, Erebor only adds a performance overhead of 4.5%-13.2%, demonstrating its practicality in terms of enabling strong data sandboxing in modern cloud machines.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c085737c-237d-468a-84ea-969286e17b4dCited by top-tier papers5
- ρHammer: Reviving RowHammer Attacks on New Architectures via PrefetchingWeijie Chen, Shan Tang, Yulin Tang, Xiapu Luo et al.MICRO 2025 · 1 citation
- IOValve: Leakage-Free I/O Sandbox for Large-Scale Untrusted Data ProcessingSangho Lee, Jules Drean, Yue Tan, Marcus PeinadoCCS 2025 · 1 citation
- Characterizing Trust Boundary Vulnerabilities in TEE Container Systems: An Empirical StudyWeijie Liu, Hongbo Chen, Shuo Huai, Zhen Xu et al.FSE 2026
- GPU Travelling: Efficient Confidential Collaborative Training with TEE-Enabled GPUsShixuan Zhao, Zhongshu Gu, Salman Ahmed, Enriquillo Valdez et al.CCS 2025
- Wallet: Confidential Serverless ComputingPatrick Sabanic, Masanori Misono, Teofil Bodea, Julian Pritzi et al.NSDI 2026
Builds on27
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim et al.USENIX Security 2017 · 536 citations
- Plundervolt: Software-based Fault Injection Attacks against Intel SGXKit Murdock, David F. Oswald, Flavio D. Garcia, Jo Van Bulck et al.S&P 2020 · 369 citations
Related papers
- BadAML: Exploiting Legacy Firmware Interfaces to Compromise Confidential Virtual MachinesSatoru Takekoshi, Manami Mori, Takaaki Fukai, Takahiro ShinagawaCCS 2025
- Veil: A Protected Services Framework for Confidential Virtual MachinesAdil Ahmad, Botong Ou, Congyu Liu, Xiaokuan Zhang et al.ASPLOS 2023 · 12 citations
- BlackBox: A Container Security Monitor for Protecting Containers on Untrusted Operating SystemsAlexander Van't Hof, Jason NiehOSDI 2022 · 44 citations
- Design and Verification of the Arm Confidential Compute ArchitectureXupeng Li, Xuheng Li, Christoffer Dall, Ronghui Gu et al.OSDI 2022 · 60 citations
- Pave: Information Flow Control for Privacy-preserving Online Data Processing ServicesMinkyung Park, Jaeseung Choi, Hyeonmin Lee, Ted Taekyoung KwonASPLOS 2025 · 1 citation
