An Extensible Orchestration and Protection Framework for Confidential Cloud Computing

An Extensible Orchestration and Protection Framework for Confidential Cloud Computing
复制标题

DOI:
--
复制
发表时间:
2023
期刊:
--
影响因子:
--
通讯作者:
Adil Ahmad;Alex Schultz;Byoungyoung Lee;Pedro Fonseca
Adil Ahmad;Alex Schultz;Byoungyoung Lee;Pedro Fonseca
中科院分区:
其他
文献类型:
--
作者:
Adil Ahmad;Alex Schultz;Byoungyoung Lee;Pedro Fonseca

文献摘要

被引文献

相似文献

机密的计算解决方案对于解决云隐私问题至关重要通过提供一个全面,安全的管理机场级的仪器框架,能够监视所有飞地-OS交互并实施的保护服务,从而限制。 EOPF克服了几个挑战,包括在使用EOPF的情况下弥合管理障碍和SGX之间的语义差距,并证明了框架的共同点评估表明,当默认状态下,EOPF的性能开销非常低(<2%),而仅在强度,完工时,EOPF仅在其默认状态下(Spec上的几何平均值为17%)启用了侧通道防御,使EOPF成为云的高效且实用的解决方案。
Confidential computing solutions are crucial to address the cloud privacy concerns. Although SGX has witnessed significant adoption in the cloud, the reliance on hardware implementation is restrictive for cloud providers in terms of orchestrating deployments and providing stronger security to their clients’ enclaves. eOPF addresses this limitation by providing a comprehensive, secure hypervisor-level instrumentation framework with the ability to monitor all enclave-OS interactions and implement protected services. eOPF overcomes several challenges including bridging the semantic gap be-tween the hypervisor and SGX and attesting the co-location of the framework with enclaves. Using eOPF, we implement two protected services that provide platform resource orchestration and complementary enclave side-channel defense. Our evaluation shows that eOPF incurs very low performance overhead (<2%) in its default state and only modest overhead (geometric mean of 17% on SPEC) when strong, complementary side-channel defenses are enabled, making eOPF an efficient and practical solution for the cloud.