SKernel: An Elastic and Efficient Secure Container System at Scale with a Split-Kernel Architecture
Xiaohu Chai, Keyang Hu, Jianfeng Tan, Tiwei Bie, Guotao Tan, Tianyu Zhou, Anqi Shen, Dawei Shen, Xinyao Yang, Xin Chen, Xu Wang, Feng Yu
Abstract
Secure containers leverage hardware virtualization to isolate container sandboxes, enabling dedicated guest kernels to mitigate shared kernel attacks prevalent in traditional systems. However, existing approaches struggle with a fundamental trade-off: VM-based solutions (e.g., Kata) prioritize performance but lack elasticity and on-demand usage for volatile and bursty workloads, while lightweight methods (e.g., gVisor) rely on the host kernel for dynamic resource management at the cost of significant performance degradation due to guest-host dependencies.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get ee67e40a-cf20-4059-b79d-0c0121362657Related papers
- CofferOS: Hardening OS-level Virtualization with RustMinkyu Jung, Chanshin Kwak, Junho Ahn, Sunho Park et al.EuroSys 2026
- A Hardware-Software Co-Design for Efficient Secure ContainersJiacheng Shi, Yang Yu, Jinyu Gu, Yubin XiaEuroSys 2025
- JANUS: Cross-World, Cooperative Nested Virtualization for Secure ContainersJiangshan Lai, Hang Huang, Quan Xu, Zhen Ren et al.OSDI 2026
- MettEagle: Costs and Benefits of Implementing Containers on MicrokernelsTill Miemietz, Viktor Reusch, Matthias Hille, Lars Wrenger et al.OSDI 2025 · 2 citations
- Attacks are Forwarded: Breaking the Isolation of MicroVM-based Containers Through Operation ForwardingJietao Xiao, Nanzi Yang, Wenbo Shen, Jinku Li et al.USENIX Security 2023
