Towards (Really) Safe and Fast Confidential I/O

Towards (Really) Safe and Fast Confidential I/O
复制标题

DOI:
10.1145/3593856.3595913
复制
发表时间:
2023-06
期刊:
Proceedings of the 19th Workshop on Hot Topics in Operating Systems
影响因子:
--
通讯作者:
Hugo Lefeuvre;D. Chisnall;Marios Kogias;Pierre Olivier
Hugo Lefeuvre;D. Chisnall;Marios Kogias;Pierre Olivier
中科院分区:
其他
文献类型:
--
作者:
Hugo Lefeuvre;D. Chisnall;Marios Kogias;Pierre Olivier

文献摘要

相似文献

机密云计算使云租户能够不信任他们的服务提供商。要实现提供具体安全保证的机密计算解决方案,不仅需要强大的机制,还需要精心设计的软件接口。在本文中,我们观察到,处于性能和安全拉锯战中的机密I/O接口,在面临接口漏洞和不可信主机可观察性的同时,无法解决这两个问题。我们讨论了保密计算中的安全I/O接口问题及其影响和挑战,并设计了实现既安全又快速的保密I/O接口的研究途径。
Confidential cloud computing enables cloud tenants to distrust their service provider. Achieving confidential computing solutions that provide concrete security guarantees requires not only strong mechanisms, but also carefully designed software interfaces. In this paper, we make the observation that confidential I/O interfaces, caught in the tug-of-war between performance and security, fail to address both at a time when confronted to interface vulnerabilities and observability by the untrusted host. We discuss the problem of safe I/O interfaces in confidential computing, its implications and challenges, and devise research paths to achieve confidential I/O interfaces that are both safe and fast.