Civet: An Efficient Java Partitioning Framework for Hardware Enclaves
Chia-Che Tsai, Jeongseok Son, Bhushan Jain, John McAvey, Raluca Ada Popa, Donald E. Porter
摘要
Hardware enclaves are designed to execute small pieces of sensitive code or to operate on sensitive data, in isolation from larger, less trusted systems. Partitioning a large, legacy application requires significant effort. Partitioning an application written in a managed language, such as Java, is more challenging because of mutable language characteristics, extensive code reachability in class libraries, and the inevitability of using a heavyweight runtime. Civet is a framework for partitioning Java applications into enclaves. Civet reduces the number of lines of code in the enclave and uses language-level defenses, including deep type checks and dynamic taint-tracking, to harden the enclave interface. Civet also contributes a partitioned Java runtime design, including a garbage collection design optimized for the peculiarities of enclaves. Civet is efficient for data-intensive workloads; partitioning a Hadoop mapper reduces the enclave overhead from 10× to 16-22% without taint-tracking or 70-80% with taint-tracking. HDFS Yarn Scheduler Thread Commodity JVM MapTask(s) ReduceTask(s) map(K,V,Context) reduce(K,V[],Context) JNI Standard Classes Direct Invocation Enclave Protection Thread Thread Thread Thread Thread (a) Non-partitioned model needs to run the entire Hadoop framework in an enclave. HDFS Yarn Scheduler Thread Commodity JVM MapTask(s) ReduceTask(s) JNI Standard Classes Partitioned JVM Enclave Invocation Direct Invocation Enclave Protection Thread Thread Thread Thread Thread map(K,V,Context) reduce(K,V[],Context)
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper13
- Scalable Memory Protection in the PENGLAI EnclaveErhu Feng, Xu Lu, Dong Du, Bicheng Yang 等OSDI 2021 · 被引用 126 次
- Twine: An Embedded Trusted Runtime for WebAssemblyJämes Ménétrey, Marcelo Pasin, Pascal Felber, Valerio SchiavoniICDE 2021 · 被引用 58 次
- CubicleOS: a library OS with software componentisation for practical isolationVasily A. Sartakov, Lluís Vilanova, Peter R. PietzuchASPLOS 2021 · 被引用 38 次
- Nested Enclave: Supporting Fine-grained Hierarchical Isolation with SGXJoongun Park, Naegyeong Kang, Taehoon Kim, Youngjin Kwon 等ISCA 2020 · 被引用 33 次
- HyperEnclave: An Open and Cross-platform Trusted Execution EnvironmentYuekai Jia, Shuang Liu, Wenhao Wang, Yu Chen 等USENIX ATC 2022 · 被引用 24 次
它引用的顶会 Paper7
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 被引用 649 次
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim 等USENIX Security 2017 · 被引用 536 次
- Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGXWenhao Wang, Guoxing Chen, Xiaorui Pan, Yinqian Zhang 等CCS 2017 · 被引用 403 次
- Telling Your Secrets without Page Faults: Stealthy Page Table-Based Attacks on Enclaved ExecutionJo Van Bulck, Nico Weichbrodt, Rüdiger Kapitza, Frank Piessens 等USENIX Security 2017 · 被引用 316 次
相关 Paper
- Weave: Efficient and Expressive Oblivious Analytics at ScaleMahdi Soleimani, Grace Jia, Anurag KhandelwalOSDI 2025 · 被引用 1 次
- Lejacon: A Lightweight and Efficient Approach to Java Confidential Computing on SGXXinyuan Miao, Ziyi Lin, Shaojun Wang, Lei Yu 等ICSE 2023 · 被引用 1 次
- MULCOTAINT: Towards Efficient Multi-tag Dynamic Taint Analysis via Hardware/Software Co-designBing Qi, Yi Yang, Xiangkun Jia, Zhengpin Qian 等USENIX Security 2026
- Isolating functions at the hardware limit with virtinesNicholas C. Wanninger, Joshua J. Bowden, Kirtankumar Shetty, Ayush Garg 等EuroSys 2022 · 被引用 17 次
- VirTEE: a full backward-compatible TEE with native live migration and secure I/OJianqiang Wang, Pouya Mahmoody, Ferdinand Brasser, Patrick Jauernig 等DAC 2022 · 被引用 11 次
