CHANCEL: Efficient Multi-client Isolation Under Adversarial Programs
Adil Ahmad, Juhee Kim, Jaebaek Seo, Insik Shin, Pedro Fonseca, Byoungyoung Lee
摘要
Intel SGX aims to provide the confidentiality of user data on untrusted cloud machines. However, applications that process confidential user data may contain bugs that leak information or be programmed maliciously to collect user data. Existing research that attempts to solve this problem does not consider multi-client isolation in a single enclave. We show that by not supporting such in-enclave isolation, they incur considerable slowdown when concurrently processing multiple clients in different enclave processes, due to the limitations of SGX. This paper proposes CHANCEL, a sandbox designed for multi-client isolation within a single SGX enclave. In particular, CHANCEL allows a program’s threads to access both a per-thread memory region and a shared read-only memory region while servicing requests. Each thread handles requests from a single client at a time and is isolated from other threads, using a MultiClient Software Fault Isolation (MCSFI) scheme. Furthermore, CHANCEL supports various in-enclave services such as an inmemory file system and shielded client communication to ensure complete mediation of the program’s interactions with the outside world. We implemented CHANCEL and evaluated it on SGX hardware using both micro-benchmarks and realistic target scenarios, including private information retrieval and product recommendation services. Our results show that CHANCEL outperforms a baseline multi-process sandbox by 4.06− 53.70× on micro-benchmarks and 0.02−21.18× on realistic workloads while providing strong security guarantees.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- KIT: Testing OS-Level Virtualization for Functional Interference BugsCongyu Liu, Sishuai Gong, Pedro FonsecaASPLOS 2023 · 被引用 16 次
- Veil: A Protected Services Framework for Confidential Virtual MachinesAdil Ahmad, Botong Ou, Congyu Liu, Xiaokuan Zhang 等ASPLOS 2023 · 被引用 12 次
- Cerberus: A Formal Approach to Secure and Efficient Enclave Memory SharingDayeol Lee, Kevin Cheang, Alexander Thomas, Catherine Lu 等CCS 2022 · 被引用 11 次
- An Extensible Orchestration and Protection Framework for Confidential Cloud ComputingAdil Ahmad, Alex Schultz, Byoungyoung Lee, Pedro FonsecaOSDI 2023 · 被引用 10 次
- A Secure, Fast, and Resource-Efficient Serverless Platform with Function REWINDJaehyun Song, Bumsuk Kim, Minwoo Kwak, Byoungyoung Lee 等USENIX ATC 2024 · 被引用 5 次
它引用的顶会 Paper22
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 被引用 649 次
- Oblivious Multi-Party Machine Learning on Trusted ProcessorsOlga Ohrimenko, Felix Schuster, Cédric Fournet, Aastha Mehta 等USENIX Security 2016 · 被引用 594 次
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim 等USENIX Security 2017 · 被引用 536 次
相关 Paper
- SGXLock: Towards Efficiently Establishing Mutual Distrust Between Host Application and Enclave for SGXYuan Chen, Jiaqi Li, Guorui Xu, Yajin Zhou 等USENIX Security 2022
- IntraFuzz: Coverage-Guided Intra-Enclave Fuzzing for Intel SGX ApplicationsJinhua Cui, Qiao Peng, Yiwen Yao, Ke Ye 等DAC 2025 · 被引用 1 次
- T-SGX: Eradicating Controlled-Channel Attacks Against Enclave ProgramsMing-Wei Shih, Sangho Lee, Taesoo Kim, Marcus PeinadoNDSS 2017 · 被引用 431 次
- Strong and Efficient Cache Side-Channel Protection using Hardware Transactional MemoryDaniel Gruss, Julian Lettner, Felix Schuster, Olga Ohrimenko 等USENIX Security 2017 · 被引用 254 次
- Composable Cachelets: Protecting Enclaves from Cache Side-Channel AttacksDaniel Townley, Kerem Arikan, Yu David Liu, Dmitry Ponomarev 等USENIX Security 2022
