Scalable Memory Protection in the PENGLAI Enclave
Erhu Feng, Xu Lu, Dong Du, Bicheng Yang, Xueqiang Jiang, Yubin Xia, Binyu Zang, Haibo Chen
摘要
Secure hardware enclaves have been widely used for protecting security-critical applications in the cloud. However, existing enclave designs fail to meet the requirements of scalability demanded by new scenarios like serverless computing, mainly due to the limitations in their secure memory protection mechanisms, including static allocation, restricted capacity and high-cost initialization. In this paper, we propose a software-hardware co-design to support dynamic, fine-grained, large-scale secure memory as well as fast-initialization. We first introduce two new hardware primitives: 1) Guarded Page Table (GPT), which protects page table pages to support page-level secure memory isolation; 2) Mountable Merkle Tree (MMT), which supports scalable integrity protection for secure memory. Upon these two primitives, our system can scale to thousands of concurrent enclaves with high resource utilization and eliminate the high-cost initialization of secure memory using fork-style enclave creation without weakening the security guarantees.
We have implemented a prototype of our design based on PENGLAI [24], an open-sourced enclave system for RISC-V. The experimental results show that PENGLAI can support 1,000s enclave instances running concurrently and scale up to 512GB secure memory with both encryption and integrity protection. The overhead of GPT is 5% for memoryintensive workloads (e.g., Redis) and negligible for CPUintensive workloads (e.g., RV8 and Coremarks). PENGLAI also reduces the latency of secure memory initialization by three orders of magnitude and gains 3.6x speedup for realworld applications (e.g., MapReduce).
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper44
- Secure and Lightweight Deduplicated Storage via Shielded Deduplication-Before-EncryptionZuoru Yang, Jingwei Li, Patrick P. C. LeeUSENIX ATC 2022 · 被引用 46 次
- ACAI: Protecting Accelerator Execution with Arm Confidential Computing ArchitectureSupraja Sridhara, Andrin Bertschi, Benedict Schlüter, Mark Kuhne 等USENIX Security 2024 · 被引用 36 次
- PPMLAC: high performance chipset architecture for secure multi-party computationXing Zhou, Zhilei Xu, Cong Wang, Mingyu GaoISCA 2022 · 被引用 23 次
- Battering RAM: Low-Cost Interposer Attacks on Confidential Computing via Dynamic Memory AliasingJesse De Meulemeester, David F. Oswald, Ingrid Verbauwhede, Jo Van BulckS&P 2026 · 被引用 20 次
- SEVeriFast: Minimizing the root of trust for fast startup of SEV microVMsBenjamin Holmes, Jason Waterman, Dan WilliamsASPLOS 2024 · 被引用 14 次
它引用的顶会 Paper17
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Serverless in the Wild: Characterizing and Optimizing the Serverless Workload at a Large Cloud ProviderMohammad Shahrad, Rodrigo Fonseca, Iñigo Goiri, Gohar Irfan Chaudhry 等USENIX ATC 2020 · 被引用 946 次
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 被引用 649 次
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic 等EuroSys 2020 · 被引用 381 次
相关 Paper
- SecTEE: A Software-based Approach to Secure Enclave Architecture Using TEEShijun Zhao, Qianying Zhang, Yu Qin, Wei Feng 等CCS 2019 · 被引用 95 次
- Efficient Distributed Secure Memory with Migratable Merkle TreeErhu Feng, Dong Du, Yubin Xia, Haibo ChenHPCA 2023 · 被引用 14 次
- Accelerating Extra Dimensional Page Walks for Confidential ComputingDong Du, Bicheng Yang, Yubin Xia, Haibo ChenMICRO 2023 · 被引用 7 次
- Confidential Serverless Made Efficient with Plug-In EnclavesMingyu Li, Yubin Xia, Haibo ChenISCA 2021 · 被引用 32 次
- Distributed Memory Guard: Enabling Secure Enclave Computing in NoC-based ArchitecturesGhada Dessouky, Mihailo Isakov, Michel A. Kinsy, Pouya Mahmoody 等DAC 2021 · 被引用 3 次
