MlsDisk: Trusted Block Storage for TEEs Based on Layered Secure Logging
Erci Xu, Xinyi Yu, Lujia Yin, Xinyuan Luo, Shaowei Song, Qingsong Chen, Shoumeng Yan, Jiwu Shu, Hongliang Tian, Yiming Zhang
摘要
Trusted Execution Environments (TEEs) enable users to run sensitive applications in private memory regions. SGX-PFS is the state-of-the-art secure storage solution for TEEs that ensures data confidentiality, integrity, freshness, and consistency (CIFC). Unfortunately, SGX-PFS uses Merkle Hash Trees to protect in-place persisted data and suffers from poor I/O performance and is thus of limited use in practice.
This paper presents MlsDisk, a secure virtual disk that adopts out-of-place logging to provide efficient trusted block storage for TEEs. The challenge is that the complexity of indexing and garbage collection (GC) in log-structured storage makes it difficult to ensure security. We therefore adopt a layered design to break down the indexing and GC into four layers of abstractions, which facilitates reasoning about CIFC properties. Evaluation shows that MlsDisk, with CIFC guarantees, outperforms SGX-PFS by 7.3×-21.1× on microbenchmarks and 1.4×-3.6× on trace-driven workloads.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper8
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic 等EuroSys 2020 · 被引用 381 次
- EnclaveDB: A Secure Database Using SGXChristian Priebe, Kapil Vaswani, Manuel CostaS&P 2018 · 被引用 329 次
- Occlum: Secure and Efficient Multitasking Inside a Single Enclave of Intel SGXYouren Shen, Hongliang Tian, Yu Chen, Kang Chen 等ASPLOS 2020 · 被引用 144 次
- VRASED: A Verified Hardware/Software Co-Design for Remote AttestationIvan De Oliveira Nunes, Karim Eldefrawy, Norrathep Rattanavipanon, Michael Steiner 等USENIX Security 2019 · 被引用 135 次
- Confidential computing for OpenPOWERGuerney D. H. Hunt, Ramachandra Pai, Michael V. Le, Hani Jamjoom 等EuroSys 2021 · 被引用 38 次
相关 Paper
- Trust-V: Toward Secure and Reliable Storage for Trusted Execution EnvironmentsSeung-Kyun Han, Jiyeon Yang, Jinsoo JangASPLOS 2026
- A Log-Structured Merge Tree-aware Message Authentication Scheme for Persistent Key-Value StoresIg-Jae Kim, J. Hyun Kim, Minu Chung, Hyungon Moon 等FAST 2022 · 被引用 8 次
- rkt-io: a direct I/O stack for shielded executionJörg Thalheim, Harshavardhan Unnibhavi, Christian Priebe, Pramod Bhatotia 等EuroSys 2021 · 被引用 24 次
- Aria: Tolerating Skewed Workloads in Secure In-memory Key-value StoresFan Yang, Youmin Chen, Youyou Lu, Qing Wang 等ICDE 2021 · 被引用 7 次
- Accelerating Encrypted Deduplication via SGXYanjing Ren, Jingwei Li, Zuoru Yang, Patrick P. C. Lee 等USENIX ATC 2021 · 被引用 50 次
