CubicleOS: a library OS with software componentisation for practical isolation
Vasily A. Sartakov, Lluís Vilanova, Peter R. Pietzuch
Abstract
Library OSs have been proposed to deploy applications isolated inside containers, VMs, or trusted execution environments. They often follow a highly modular design in which third-party components are combined to offer the OS functionality needed by an application, and they are customised at compilation and deployment time to fit application requirements. Yet their monolithic design lacks isolation across components: when applications and OS components contain security-sensitive data (e.g., cryptographic keys or user data), the lack of isolation renders library OSs open to security breaches via malicious or vulnerable third-party components.
We describe CubicleOS, a library OS that isolates components in the system while maintaining the simple, monolithic development approach of library composition. CubicleOS allows isolated components, called cubicles, to share data dynamically with other components. It provides spatial memory isolation at the granularity of function calls by using Intel MPK at user-level to isolate components. At the same time, it supports zero-copy data access across cubicles with feature-rich OS functionality. Our evaluation shows that CubicleOS introduces moderate end-to-end performance overheads in complex applications: 2× for the I/O-intensive NGINX web server with 8 partitions, and 1.7-8× for the SQLite database engine with 7 partitions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e96031b4-94af-4b4d-9eda-da648e78fc34Cited by top-tier papers24
- BlackBox: A Container Security Monitor for Protecting Containers on Untrusted Operating SystemsAlexander Van't Hof, Jason NiehOSDI 2022 · 44 citations
- FlexOS: towards flexible OS isolationHugo Lefeuvre, Vlad-Andrei Badoiu, Alexander Jung, Stefan Lucian Teodorescu et al.ASPLOS 2022 · 36 citations
- You shall not (by)pass!: practical, secure, and fast PKU-based sandboxingAlexios Voulimeneas, Jonas Vinck, Ruben Mechelinck, Stijn VolckaertEuroSys 2022 · 33 citations
- CAP-VMs: Capability-Based Isolation and Sharing in the CloudVasily A. Sartakov, Lluís Vilanova, David M. Eyers, Takahiro Shinagawa et al.OSDI 2022 · 24 citations
- LemonNFV: Consolidating Heterogeneous Network Functions at Line SpeedHao Li, Yihan Dang, Guangda Sun, Guyue Liu et al.NSDI 2023 · 21 citations
Builds on4
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler et al.USENIX Security 2019 · 247 citations
- BreakApp: Automated, Flexible Application CompartmentalizationNikos Vasilakis, Ben Karel, Nick Roessler, Nathan Dautenhahn et al.NDSS 2018 · 66 citations
- Harmonizing Performance and Isolation in Microkernels with Efficient Intra-kernel Isolation and CommunicationJinyu Gu, Xinyue Wu, Wentai Li, Nian Liu et al.USENIX ATC 2020 · 51 citations
- Civet: An Efficient Java Partitioning Framework for Hardware EnclavesChia-Che Tsai, Jeongseok Son, Bhushan Jain, John McAvey et al.USENIX Security 2020
Related papers
- EKC: A Portable and Extensible Kernel Compartment for De-Privileging Commodity OSJiaqin Yan, Qiujiang Chen, Shuai Zhou, Yuke Peng et al.USENIX Security 2025
- Enclosure: language-based restriction of untrusted librariesAdrien Ghosn, Marios Kogias, Mathias Payer, James R. Larus et al.ASPLOS 2021 · 33 citations
- Turning Linux into a High-Performance Library OS with FluxKaifu Tian, Youjie Zheng, Yiren Zhang, Yuyang You et al.SOSP 2026
- Secure Caches for Compartmentalized SoftwareKerem Arikan, Huaxin Tang, Williams Zhang Cen, Yu David Liu et al.USENIX Security 2025
- BULKHEAD: Secure, Scalable, and Efficient Kernel Compartmentalization with PKSYinggang Guo, Zicheng Wang, Weiheng Bai, Qingkai Zeng et al.NDSS 2025
