Twine: An Embedded Trusted Runtime for WebAssembly
Jämes Ménétrey, Marcelo Pasin, Pascal Felber, Valerio Schiavoni
摘要
WebAssembly is an Increasingly popular lightweight binary instruction format, which can be efficiently embedded and sandboxed. Languages like C, C++, Rust, Go, and many others can be compiled into WebAssembly. This paper describes Twine, a WebAssembly trusted runtime designed to execute unmodified, language-independent applications. We leverage Intel SGX to build the runtime environment without dealing with language-specific, complex APIs. While SGX hardware provides secure execution within the processor, Twine provides a secure, sandboxed software runtime nested within an SGX enclave, featuring a WebAssembly system interface (WASI) for compatibility with unmodified WebAssembly applications. We evaluate Twine with a large set of general-purpose benchmarks and real-world applications. In particular, we used Twine to implement a secure, trusted version of SQLite, a well-known full-fledged embeddable database. We believe that such a trusted database would be a reasonable component to build many larger application services. Our evaluation shows that SQLite can be fully executed inside an SGX enclave via WebAssembly and existing system interface, with similar average performance overheads. We estimate that the performance penalties measured are largely compensated by the additional security guarantees and its full compatibility with standard WebAssembly. An indepth analysis of our results indicates that performance can be greatly improved by modifying some of the underlying libraries. We describe and implement one such modification in the paper, showing up to 4.1 × speedup. Twine is open-source, available at GitHub along with instructions to reproduce our experiments.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- Exploring Missed Optimizations in WebAssembly OptimizersZhibo Liu, Dongwei Xiao, Zongjie Li, Shuai Wang 等ISSTA 2023 · 被引用 24 次
- HyperEnclave: An Open and Cross-platform Trusted Execution EnvironmentYuekai Jia, Shuang Liu, Wenhao Wang, Yu Chen 等USENIX ATC 2022 · 被引用 24 次
- Static Stack-Preserving Intra-Procedural Slicing of WebAssembly BinariesQuentin Stiévenart, David W. Binkley, Coen De RooverICSE 2022 · 被引用 18 次
- On (the Lack of) Code Confidentiality in Trusted Execution EnvironmentsIvan Puddu, Moritz Schneider, Daniele Lain, Stefano Boschetto 等S&P 2024 · 被引用 14 次
- Revealing Performance Issues in Server-Side WebAssembly Runtimes Via Differential TestingShuyao Jiang, Ruiying Zeng, Zihao Rao, Jiazhen Gu 等ASE 2023 · 被引用 12 次
它引用的顶会 Paper6
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic 等EuroSys 2020 · 被引用 381 次
- EnclaveDB: A Secure Database Using SGXChristian Priebe, Kapil Vaswani, Manuel CostaS&P 2018 · 被引用 329 次
- OBLIVIATE: A Data Oblivious Filesystem for Intel SGXAdil Ahmad, Kyungtae Kim, Muhammad Ihsanulhaq Sarfaraz, Byoungyoung LeeNDSS 2018 · 被引用 144 次
- Towards Memory Safe Enclave Programming with Rust-SGXHuibo Wang, Pei Wang, Yu Ding, Mingshen Sun 等CCS 2019 · 被引用 86 次
- Civet: An Efficient Java Partitioning Framework for Hardware EnclavesChia-Che Tsai, Jeongseok Son, Bhushan Jain, John McAvey 等USENIX Security 2020
相关 Paper
- WaVe: a verifiably secure WebAssembly sandboxing runtimeEvan Johnson, Evan Laufer, Zijie Zhao, Dan Gohman 等S&P 2023
- VeriDB: An SGX-based Verifiable DatabaseWenchao Zhou, Yifan Cai, Yanqing Peng, Sheng Wang 等SIGMOD 2021 · 被引用 52 次
- Provably-Safe Multilingual Software Sandboxing using WebAssemblyJay Bosamiya, Wen Shih Lim, Bryan ParnoUSENIX Security 2022
- T-SGX: Eradicating Controlled-Channel Attacks Against Enclave ProgramsMing-Wei Shih, Sangho Lee, Taesoo Kim, Marcus PeinadoNDSS 2017 · 被引用 431 次
- SGXLock: Towards Efficiently Establishing Mutual Distrust Between Host Application and Enclave for SGXYuan Chen, Jiaqi Li, Guorui Xu, Yajin Zhou 等USENIX Security 2022
