ORC: Increasing Cloud Memory Density via Object Reuse with Capabilities

ORC: Increasing Cloud Memory Density via Object Reuse with Capabilities
复制标题

DOI:
--
复制
发表时间:
2023
期刊:
--
影响因子:
--
通讯作者:
V. Sartakov;Lluís Vilanova;Munir Geden;D. Eyers;Takahiro Shinagawa;P. Pietzuch
V. Sartakov;Lluís Vilanova;Munir Geden;D. Eyers;Takahiro Shinagawa;P. Pietzuch
中科院分区:
其他
文献类型:
--
作者:
V. Sartakov;Lluís Vilanova;Munir Geden;D. Eyers;Takahiro Shinagawa;P. Pietzuch

文献摘要

相似文献

云环境托管许多租户,并且通常租户执行的应用程序二进制文件和库之间存在大量重叠。因此,内存重复数据删除可以通过仅为共享二进制文件分配一次内存来增加内存密度。然而,现有的重复数据删除方法要么依赖于共享OS来对二进制对象进行重复数据删除,这提供了不可接受的弱隔离;要么在存储器页面级别利用基于管理程序的重复数据删除,这对要共享的对象的语义是盲目的。我们描述了对象重用与能力(ORC),它支持租户之间的细粒度共享二进制对象,同时通过一个小的可信计算基础(TCB)强烈隔离租户。ORC使用对内存功能的硬件支持来隔离租户,这允许多个租户安全地访问共享对象。由于ORC通过功能在单个地址空间内共享二进制对象,因此在加载共享对象时,它使用新的重定位类型来使用线程本地存储创建每个租户的状态。ORC支持不受信任的客户机在其TCB之外加载对象,仅验证加载数据的安全性。我们的实验表明,与基于虚拟机管理程序的去重复数据删除相比,ORC实现了更高的内存密度和更低的性能开销。
Cloud environments host many tenants, and typically there is substantial overlap between the application binaries and libraries executed by tenants. Thus, memory de-duplication can increase memory density by allocating memory for shared binaries only once. Existing de-duplication approaches, however, either rely on a shared OS to de-deduplicate binary objects, which provides unacceptably weak isolation; or exploit hypervisor-based de-duplication at the level of memory pages, which is blind to the semantics of the objects to be shared. We describe Object Reuse with Capabilities (ORC) , which supports the fine-grained sharing of binary objects between tenants, while isolating tenants strongly through a small trusted computing base (TCB). ORC uses hardware support for memory capabilities to isolate tenants, which permits shared objects to be accessible to multiple tenants safely. Since ORC shares binary objects within a single address space through capabilities, it uses a new relocation type to create per-tenant state using thread-local storage when loading shared objects. ORC supports the loading of objects by an untrusted guest, outside of its TCB, only verifying the safety of the loaded data. Our experiments show that, compared to hypervisor-based de-deduplication, ORC achieves a higher memory density with a lower performance overhead.