Scalable Memory Protection in the PENGLAI Enclave
Erhu Feng, Xu Lu, Dong Du, Bicheng Yang, Xueqiang Jiang, Yubin Xia, Binyu Zang, Haibo Chen
Abstract
Secure hardware enclaves have been widely used for protecting security-critical applications in the cloud. However, existing enclave designs fail to meet the requirements of scalability demanded by new scenarios like serverless computing, mainly due to the limitations in their secure memory protection mechanisms, including static allocation, restricted capacity and high-cost initialization. In this paper, we propose a software-hardware co-design to support dynamic, fine-grained, large-scale secure memory as well as fast-initialization. We first introduce two new hardware primitives: 1) Guarded Page Table (GPT), which protects page table pages to support page-level secure memory isolation; 2) Mountable Merkle Tree (MMT), which supports scalable integrity protection for secure memory. Upon these two primitives, our system can scale to thousands of concurrent enclaves with high resource utilization and eliminate the high-cost initialization of secure memory using fork-style enclave creation without weakening the security guarantees.
We have implemented a prototype of our design based on PENGLAI [24], an open-sourced enclave system for RISC-V. The experimental results show that PENGLAI can support 1,000s enclave instances running concurrently and scale up to 512GB secure memory with both encryption and integrity protection. The overhead of GPT is 5% for memoryintensive workloads (e.g., Redis) and negligible for CPUintensive workloads (e.g., RV8 and Coremarks). PENGLAI also reduces the latency of secure memory initialization by three orders of magnitude and gains 3.6x speedup for realworld applications (e.g., MapReduce).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext faf69d3b-4e5c-4cf7-9783-b827c5e766acCited by top-tier papers44
- Secure and Lightweight Deduplicated Storage via Shielded Deduplication-Before-EncryptionZuoru Yang, Jingwei Li, Patrick P. C. LeeUSENIX ATC 2022 · 46 citations
- ACAI: Protecting Accelerator Execution with Arm Confidential Computing ArchitectureSupraja Sridhara, Andrin Bertschi, Benedict Schlüter, Mark Kuhne et al.USENIX Security 2024 · 36 citations
- PPMLAC: high performance chipset architecture for secure multi-party computationXing Zhou, Zhilei Xu, Cong Wang, Mingyu GaoISCA 2022 · 23 citations
- Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory AliasingJesse De Meulemeester, David F. Oswald, Ingrid Verbauwhede, Jo Van BulckS&P 2026 · 20 citations
- SEVeriFast: Minimizing the root of trust for fast startup of SEV microVMsBenjamin Holmes, Jason Waterman, Dan WilliamsASPLOS 2024 · 14 citations
Builds on17
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Serverless in the Wild: Characterizing and Optimizing the Serverless Workload at a Large Cloud ProviderMohammad Shahrad, Rodrigo Fonseca, Iñigo Goiri, Gohar Irfan Chaudhry et al.USENIX ATC 2020 · 946 citations
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 649 citations
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic et al.EuroSys 2020 · 381 citations
Related papers
- SecTEE: A Software-based Approach to Secure Enclave Architecture Using TEEShijun Zhao, Qianying Zhang, Yu Qin, Wei Feng et al.CCS 2019 · 95 citations
- Efficient Distributed Secure Memory with Migratable Merkle TreeErhu Feng, Dong Du, Yubin Xia, Haibo ChenHPCA 2023 · 14 citations
- Accelerating Extra Dimensional Page Walks for Confidential ComputingDong Du, Bicheng Yang, Yubin Xia, Haibo ChenMICRO 2023 · 7 citations
- Confidential Serverless Made Efficient with Plug-In EnclavesMingyu Li, Yubin Xia, Haibo ChenISCA 2021 · 32 citations
- Distributed Memory Guard: Enabling Secure Enclave Computing in NoC-based ArchitecturesGhada Dessouky, Mihailo Isakov, Michel A. Kinsy, Pouya Mahmoody et al.DAC 2021 · 3 citations
