Nested SEV: Secure and Generic SEV Support for Nested Virtualization
Kazuki Takiguchi, Kenichi Kourai
摘要
In cloud environments, sensitive information in virtual machines (VMs) is exposed to insider threats. To protect VMs from malicious cloud insiders, modern clouds provide confidential VMs based on technologies such as AMD SEV, which transparently encrypts the memory of VMs and the state of CPU registers while ensuring their integrity. However, existing SEV support is not sufficient for nested virtualization, where a guest hypervisor (L1 hypervisor) runs inside a host VM (L1 VM) managed by the host hypervisor (L0 hypervisor) and creates guest VMs (L2 VMs). This paper proposes nested SEV to provide more secure and generic SEV support for nested virtualization. Nested SEV allows SEV-enabled L2 VMs to run inside an SEV-enabled L1 VM. It supports two trust models: (1) both the L0 and L1 hypervisors are untrusted, and (2) the L0 hypervisor is untrusted but the L1 hypervisor is trusted. For these trust models, nested SEV provides two mechanisms. SEV virtualization protects L2 VMs against both the L0 and L1 hypervisors. In contrast, SEV passthrough protects them against the L0 hypervisor but allows the L1 hypervisor to access the memory of L2 VMs by sharing the SEV context. These mechanisms rely on emulation-less multiplexing and SEV context decoupling . We implemented nested SEV in three different types of hypervisors and showed that the average performance degradation ranged from 0.9% to 30% across three SEV variants.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper6
- Optimizing Nested Virtualization Performance Using Direct Virtual HardwareJin Tack Lim, Jason NiehASPLOS 2020 · 被引用 34 次
- Nested Enclave: Supporting Fine-grained Hierarchical Isolation with SGXJoongun Park, Naegyeong Kang, Taehoon Kim, Youngjin Kwon 等ISCA 2020 · 被引用 33 次
- vSGX: Virtualizing SGX Enclaves on AMD SEVShixuan Zhao, Mengyuan Li, Yinqian Zhang, Zhiqiang LinS&P 2022 · 被引用 32 次
- Bifrost: Analysis and Optimization of Network I/O Tax in Confidential Virtual MachinesDingji Li, Zeyu Mi, Chenhui Ji, Yifan Tan 等USENIX ATC 2023 · 被引用 31 次
- Hecate: Lifting and Shifting On-Premises Workloads to an Untrusted CloudXinyang Ge, Hsuan-Chi Kuo, Weidong CuiCCS 2022 · 被引用 14 次
相关 Paper
- Exploiting Unprotected I/O Operations in AMD's Secure Encrypted VirtualizationMengyuan Li, Yinqian Zhang, Zhiqiang Lin, Yan SolihinUSENIX Security 2019 · 被引用 104 次
- The Road to Trust: Building Enclaves within Confidential VMsWenhao Wang, Linke Song, Benshan Mei, Shuang Liu 等NDSS 2025
- (Mostly) Exitless VM Protection from Untrusted Hypervisor through Disaggregated Nested VirtualizationZeyu Mi, Dingji Li, Haibo Chen, Binyu Zang 等USENIX Security 2020
- One Glitch to Rule Them All: Fault Injection Attacks Against AMD's Secure Encrypted VirtualizationRobert Buhren, Hans Niklas Jacob, Thilo Krachenfels, Jean-Pierre SeifertCCS 2021
- Veil: A Protected Services Framework for Confidential Virtual MachinesAdil Ahmad, Botong Ou, Congyu Liu, Xiaokuan Zhang 等ASPLOS 2023 · 被引用 12 次
