JANUS: Cross-World, Cooperative Nested Virtualization for Secure Containers
Jiangshan Lai, Hang Huang, Quan Xu, Zhen Ren, Wenlong Hou, Wei Guo, Jia Rao, Hui Lu, Weidong Han, Jiesheng Wu, Jiang Liu, Naixuan Guan
摘要
Secure containers such as Kata Containers strengthen isolation by running each container inside a lightweight VM. On today's virtualized clouds, this creates an unavoidable form of nested virtualization with dominant cost in memory virtualization. Existing approaches entangle CPU virtualization and three-level page-table management across hypervisors, forcing frequent cross-world synchronization and producing severe overheads for mixed memory-access workloads.
We present JANUS, a cross-world, cooperative nested virtualization architecture that cleanly separates CPU and memory virtualization responsibilities. JANUS performs all guest world switches entirely within the guest hypervisor through a lightweight switcher mechanism, while delegating all memory translation to the host hypervisor. This separation removes the host from the critical path of CPU events and eliminates the intermediate shadow or nested page tables that burden existing designs. JANUS introduces several key techniques, including VMFUNC-based EPTP switching for trap-free transitions between guest and nested-guest address spaces; a shadow-root mechanism that protects world-switch integration while allowing direct updates to the nested guest's page tables; and in-guest virtualization exception handling that enables the guest hypervisor to resolve second-level faults with only a single lightweight host interaction. Evaluations demonstrate that JANUS delivers an average performance improvement of 144% over PVM and 28.6% over KVM-based nested virtualization for real-world applications, and imposes less than 5% overhead compared to native containers in production deployment. JANUS demonstrates that rethinking nested virtualization around cross-world cooperation yields strong isolation with near-native container performance.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper18
- RunD: A Lightweight Secure Container Runtime for High-density Deployment and High-concurrency Startup in Serverless ComputingZijun Li, Jiagan Cheng, Quan Chen, Eryu Guan 等USENIX ATC 2022 · 被引用 106 次
- Houdini's Escape: Breaking the Resource Rein of Linux Control GroupsXing Gao, Zhongshu Gu, Zhengfa Li, Hani Jamjoom 等CCS 2019 · 被引用 62 次
- BlackBox: A Container Security Monitor for Protecting Containers on Untrusted Operating SystemsAlexander Van't Hof, Jason NiehOSDI 2022 · 被引用 44 次
- High-density Multi-tenant Bare-metal CloudXiantao Zhang, Xiao Zheng, Zhi Wang, Hang Yang 等ASPLOS 2020 · 被引用 39 次
- Optimizing Nested Virtualization Performance Using Direct Virtual HardwareJin Tack Lim, Jason NiehASPLOS 2020 · 被引用 34 次
相关 Paper
- Accelerating Nested Virtualization with HyperTurtleOri Ben Zur, Jakob Krebs, Shai Aviram Bergman, Mark SilbersteinUSENIX ATC 2025 · 被引用 2 次
- Translation Pass-Through for Near-Native Paging Performance in VMsShai Bergman, Mark Silberstein, Takahiro Shinagawa, Peter R. Pietzuch 等USENIX ATC 2023 · 被引用 10 次
- PVM: Efficient Shadow Paging for Deploying Secure Containers in Cloud-native EnvironmentHang Huang, Jiangshan Lai, Jia Rao, Hui Lu 等SOSP 2023 · 被引用 4 次
- SKernel: An Elastic and Efficient Secure Container System at Scale with a Split-Kernel ArchitectureXiaohu Chai, Keyang Hu, Jianfeng Tan, Tiwei Bie 等EuroSys 2026 · 被引用 1 次
- A Hardware-Software Co-Design for Efficient Secure ContainersJiacheng Shi, Yang Yu, Jinyu Gu, Yubin XiaEuroSys 2025
