PVM: Efficient Shadow Paging for Deploying Secure Containers in Cloud-native Environment

PVM: Efficient Shadow Paging for Deploying Secure Containers in Cloud-native Environment
复制标题

DOI:
10.1145/3600006.3613158
复制
发表时间:
2023-10
期刊:
Proceedings of the 29th Symposium on Operating Systems Principles
影响因子:
--
通讯作者:
Hang Huang;Jiangshan Lai;J. Rao;Hui Lu;Wenlong Hou;Hang Su;Quan Xu;Jiang Zhong;Jiahao Zeng;Xu Wang;Zhengyu He;Weidong Han;Jiang Liu;Tao Ma;Song Wu
Hang Huang;Jiangshan Lai;J. Rao;Hui Lu;Wenlong Hou;Hang Su;Quan Xu;Jiang Zhong;Jiahao Zeng;Xu Wang;Zhengyu He;Weidong Han;Jiang Liu;Tao Ma;Song Wu
中科院分区:
其他
文献类型:
--
作者:
Hang Huang;Jiangshan Lai;J. Rao;Hui Lu;Wenlong Hou;Hang Su;Quan Xu;Jiang Zhong;Jiahao Zeng;Xu Wang;Zhengyu He;Weidong Han;Jiang Liu;Tao Ma;Song Wu

文献摘要

相似文献

在云本地环境中,通常将容器部署在轻型虚拟机(VM)中,以确保强大的安全隔离和隐私保护。随着对自定义云服务的需求不断增长,第三方供应商正在转向基础架构-AS-AS-Service(IAAS)云提供商,以构建自己的云本地平台,因此需要运行VM或托管在另一个从IAAS云中租用的VM实例内托管容器的访客。 X86体系结构中最先进的嵌套虚拟化在很大程度上依赖于主机管理程序,可以将硬件虚拟化支持向来宾管理员公开,这不仅使云管理复杂化,而且还引起了人们对主机管理程序攻击表面增加的担忧。本文介绍了PVM的设计和实现,PVM是KVM的高性能来宾管理程序,它对主机管理程序透明,并且没有硬件虚拟化支持。 PVM利用了两个关键设计:1)客人和来宾管理程序之间的最小共享内存区域,以促进不同特权级别之间的状态过渡和2)有效的影子页面设计,以降低记忆虚拟化的成本。 Alibaba Cloud已采用PVM,以每天托管成千上万的安全容器。我们的实验表明,PVM明显胜过KVM中当前嵌套虚拟化用于内存虚拟化,尤其是对于并发工作负载,同时保持了CPU和I/O虚拟化的可比性。
In cloud-native environments, containers are often deployed within lightweight virtual machines (VMs) to ensure strong security isolation and privacy protection. With the growing demand for customized cloud services, third-party vendors are turning to infrastructure-as-a-service (IaaS) cloud providers to build their own cloud-native platforms, necessitating the need to run a VM or a guest that hosts containers inside another VM instance leased from an IaaS cloud. State-of-the-art nested virtualization in the x86 architecture relies heavily on the host hypervisor to expose hardware virtualization support to the guest hypervisor, not only complicating cloud management but also raising concerns about an increased attack surface at the host hypervisor. This paper presents the design and implementation of PVM, a high-performance guest hypervisor for KVM that is transparent to the host hypervisor and assumes no hardware virtualization support. PVM leverages two key designs: 1) a minimal shared memory region between the guest and guest hypervisor to facilitate state transition between different privilege levels and 2) an efficient shadow page table design to reduce the cost of memory virtualization. PVM has been adopted by Alibaba Cloud for hosting tens of thousands of secure containers on a daily basis. Our experiments demonstrate that PVM significantly outperforms current nested virtualization in KVM for memory virtualization, particularly for concurrent workloads, while maintaining comparable performance in CPU and I/O virtualization.