rkt-io: a direct I/O stack for shielded execution
Jörg Thalheim, Harshavardhan Unnibhavi, Christian Priebe, Pramod Bhatotia, Peter R. Pietzuch
摘要
The shielding of applications using trusted execution environments (TEEs) can provide strong security guarantees in untrusted cloud environments. When executing I/O operations, today's shielded execution frameworks, however, exhibit performance and security limitations: they assign resources to the I/O path inefficiently, perform redundant data copies, use untrusted host I/O stacks with security risks and performance overheads. This prevents TEEs from running modern I/O-intensive applications that require high-performance networking and storage.
We describe rkt-io (pronounced "rocket I/O"), a direct userspace network and storage I/O stack specifically designed for TEEs that combines high-performance, POSIX compatibility and security. rkt-io achieves high I/O performance by employing direct userspace I/O libraries (DPDK and SPDK) inside the TEE for kernel-bypass I/O. For efficiency, rkt-io polls for I/O events directly, by interacting with the hardware instead of relying on interrupts, and it avoids data copies by mapping DMA regions in the untrusted host memory. To maintain full Linux ABI compatibility, the userspace I/O libraries are integrated with userspace versions of the Linux VFS and network stacks inside the TEE. Since it omits the host OS from the I/O path, does not suffer from host interface/Iago attacks. Our evaluation with Intel SGX TEEs shows that rkt-io is 9× faster for networking and 7× faster for storage compared to host-(Scone) and LibOS-based (SGX-LKL) I/O approaches.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- The Demikernel Datapath OS Architecture for Microsecond-scale Datacenter SystemsIrene Zhang, Amanda Raybuck, Pratyush Patel, Kirk Olynyk 等SOSP 2021 · 被引用 83 次
- Towards High-throughput and Low-latency Billion-scale Vector Search via CPU/GPU Collaborative Filtering and Re-rankingBing Tian, Haikun Liu, Yuhang Tang, Shihai Xiao 等FAST 2025 · 被引用 49 次
- Avocado: A Secure In-Memory Distributed Storage SystemMaurice Bailleu, Dimitra Giantsidi, Vasilis Gavrielatos, Do Le Quoc 等USENIX ATC 2021 · 被引用 39 次
- Dissecting BFT Consensus: In Trusted Components we Trust!Suyash Gupta, Sajjad Rahnama, Shubham Pandey, Natacha Crooks 等EuroSys 2023 · 被引用 27 次
- ENGRAFT: Enclave-guarded Raft on Byzantine Faulty NodesWeili Wang, Sen Deng, Jianyu Niu, Michael K. Reiter 等CCS 2022 · 被引用 19 次
它引用的顶会 Paper8
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic 等EuroSys 2020 · 被引用 381 次
- Panoply: Low-TCB Linux Applications With SGX EnclavesShweta Shinde, Dat Le Tien, Shruti Tople, Prateek SaxenaNDSS 2017 · 被引用 274 次
- Hacking in Darkness: Return-oriented Programming against Secure EnclavesJae-Hyuk Lee, Jin Soo Jang, Yeongjin Jang, Nohyun Kwak 等USENIX Security 2017 · 被引用 191 次
- OBLIVIATE: A Data Oblivious Filesystem for Intel SGXAdil Ahmad, Kyungtae Kim, Muhammad Ihsanulhaq Sarfaraz, Byoungyoung LeeNDSS 2018 · 被引用 144 次
相关 Paper
- Rakis: Secure Fast I/O Primitives Across Trust Boundaries on Intel SGXMansour Alharthi, Fan Sang, Dmitrii Kuvaiskii, Mona Vij 等EuroSys 2025 · 被引用 6 次
- TCP ≈ RDMA: CPU-efficient Remote Storage Access with i10Jaehyun Hwang, Qizhe Cai, Ao Tang, Rachit AgarwalNSDI 2020 · 被引用 70 次
- sIOPMP: Scalable and Efficient I/O Protection for TEEsErhu Feng, Dahu Feng, Dong Du, Yubin Xia 等ASPLOS 2024 · 被引用 10 次
- BypassD: Enabling fast userspace access to shared SSDsSujay Yadalam, Chloe Alverti, Vasileios Karakostas, Jayneel Gandhi 等ASPLOS 2024 · 被引用 5 次
- UIEE: Secure and Efficient User-space Isolated Execution Environment for Embedded TEE SystemsHuaiyu Yan, Zhen Ling, Xuandong Chen, Xinhui Shao 等NDSS 2026 · 被引用 4 次
