Occlum: Secure and Efficient Multitasking Inside a Single Enclave of Intel SGX
Youren Shen, Hongliang Tian, Yu Chen, Kang Chen, Runji Wang, Yi Xu, Yubin Xia, Shoumeng Yan
摘要
Intel Software Guard Extensions (SGX) enables user-level code to create private memory regions called enclaves, whose code and data are protected by the CPU from software and hardware attacks outside the enclaves. Recent work introduces library operating systems (LibOSes) to SGX so that legacy applications can run inside enclaves with few or even no modifications. As virtually any non-trivial application demands multiple processes, it is essential for LibOSes to support multitasking. However, none of the existing SGX LibOSes support multitasking both securely and efficiently.
This paper presents Occlum, a system that enables secure and efficient multitasking on SGX. We implement the LibOS processes as SFI-Isolated Processes (SIPs). SFI is a software instrumentation technique for sandboxing untrusted modules (called domains). We design a novel SFI scheme named MPXbased, Multi-Domain SFI (MMDSFI) and leverage MMDSFI to enforce the isolation of SIPs. We also design an independent verifier to ensure the security guarantees of MMDSFI. With SIPs safely sharing the single address space of an enclave,
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper54
- Scalable Memory Protection in the PENGLAI EnclaveErhu Feng, Xu Lu, Dong Du, Bicheng Yang 等OSDI 2021 · 被引用 126 次
- No Privacy Left Outside: On the (In-)Security of TEE-Shielded DNN Partition for On-Device MLZiqi Zhang, Chen Gong, Yifeng Cai, Yuanyuan Yuan 等S&P 2024 · 被引用 53 次
- HECKLER: Breaking Confidential VMs with Malicious InterruptsBenedict Schlüter, Supraja Sridhara, Mark Kuhne, Andrin Bertschi 等USENIX Security 2024 · 被引用 48 次
- Falcon: A Privacy-Preserving and Interpretable Vertical Federated Learning SystemYuncheng Wu, Naili Xing, Gang Chen, Tien Tuan Anh Dinh 等VLDB 2023 · 被引用 47 次
- RULF: Rust Library Fuzzing via API Dependency Graph TraversalJianfeng Jiang, Hui Xu, Yangfan ZhouASE 2021 · 被引用 44 次
它引用的顶会 Paper7
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- T-SGX: Eradicating Controlled-Channel Attacks Against Enclave ProgramsMing-Wei Shih, Sangho Lee, Taesoo Kim, Marcus PeinadoNDSS 2017 · 被引用 431 次
- Leaky Cauldron on the Dark Land: Understanding Memory Side-Channel Hazards in SGXWenhao Wang, Guoxing Chen, Xiaorui Pan, Yinqian Zhang 等CCS 2017 · 被引用 403 次
- Panoply: Low-TCB Linux Applications With SGX EnclavesShweta Shinde, Dat Le Tien, Shruti Tople, Prateek SaxenaNDSS 2017 · 被引用 274 次
- An In-Depth Analysis of Disassembly on Full-Scale x86/x64 BinariesDennis Andriesse, Xi Chen, Victor van der Veen, Asia Slowinska 等USENIX Security 2016 · 被引用 162 次
相关 Paper
- A Hardware-Software Co-design for Efficient Intra-Enclave IsolationJinyu Gu, Bojun Zhu, Mingyu Li, Wentai Li 等USENIX Security 2022
- Klotski: Efficient Obfuscated Execution against Controlled-Channel AttacksPan Zhang, Chengyu Song, Heng Yin, Deqing Zou 等ASPLOS 2020 · 被引用 14 次
- An evaluation of methods to port legacy code to SGX enclavesKripa Shanker, Arun Joseph, Vinod GanapathyFSE 2020 · 被引用 15 次
- WorksetEnclave: Towards Optimizing Cold Starts in Confidential Serverless with Workset-Based Enclave RestoreXiaolong Yan, Qihang Zhou, Zisen Wan, Feifan Qian 等ASPLOS 2026
- SGXFuzz: Efficiently Synthesizing Nested Structures for SGX Enclave FuzzingTobias Cloosters, Johannes Willbold, Thorsten Holz, Lucas DaviUSENIX Security 2022
