Lejacon: A Lightweight and Efficient Approach to Java Confidential Computing on SGX
Xinyuan Miao, Ziyi Lin, Shaojun Wang, Lei Yu, Sanhong Li, Zihan Wang, Pengbo Nie, Yuting Chen, Beijun Shen, He Jiang
Abstract
Intel's SGX is a confidential computing technique. It allows key functionalities of C/C++/native applications to be confidentially executed in hardware enclaves. However, numerous cloud applications are written in Java. For supporting their confidential computing, state-of-the-art approaches deploy Java Virtual Machines (JVMs) in enclaves and perform confidential computing on JVMs. Meanwhile, these JVM-in-enclave solutions still suffer from serious limitations, such as heavy overheads of running JVMs in enclaves, large attack surfaces, and deep computation stacks. To mitigate the above limitations, we for-malize a Secure Closed-World (SCW) principle and then propose Lejacon, a lightweight and efficient approach to Java confidential computing. The key idea is, given a Java application, to (1) separately compile its confidential computing tasks into a bundle of Native Confidential Computing (NCC) services; (2) run the NCC services in enclaves on the Trusted Execution Environment (TEE) side, and meanwhile run the non-confidential code on a JVM on the Rich Execution Environment (REE) side. The two sides interact with each other, protecting confidential computing tasks and as well keeping the Trusted Computing Base (TCB) size small. We implement Lejacon and evaluate it against OcclumJ (a state-of-the-art JVM-in-enclave solution) on a set of benchmarks using the BouncyCastle cryptography library. The evaluation results clearly show the strengths of Lejacon: it achieves compet-itive performance in running Java confidential code in enclaves; compared with OcclumJ, Lejacon achieves speedups by up to 16.2x in running confidential code and also reduces the TCB sizes by 90+% on average.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get c5c7499d-7dc9-41f4-8699-885f7de7a8eaRelated papers
- COIN Attacks: On Insecurity of Enclave Untrusted Interfaces in SGXMustakimur Rahman Khandaker, Yueqiang Cheng, Zhi Wang, Tao WeiASPLOS 2020 · 46 citations
- A Hardware-Software Co-design for Efficient Intra-Enclave IsolationJinyu Gu, Bojun Zhu, Mingyu Li, Wentai Li et al.USENIX Security 2022
- Reusable Enclaves for Confidential Serverless ComputingShixuan Zhao, Pinshen Xu, Guoxing Chen, Mengya Zhang et al.USENIX Security 2023
- SGX-FPGA: Trusted Execution Environment for CPU-FPGA Heterogeneous ArchitectureKe Xia, Yukui Luo, Xiaolin Xu, Sheng WeiDAC 2021 · 39 citations
- WorksetEnclave: Towards Optimizing Cold Starts in Confidential Serverless with Workset-Based Enclave RestoreXiaolong Yan, Qihang Zhou, Zisen Wan, Feifan Qian et al.ASPLOS 2026
