计算机科学
操作系统
虚拟化
管理程序
国际商用机器公司
固件
架空(工程)
过程(计算)
虚拟机
嵌入式系统
服务器
可信计算
开源
软件
云计算
纳米技术
材料科学
作者
Yuekai Jia,Shuang Liu,Wenhao Wang,Yu Chen,Zhengde Zhai,Shoumeng Yan,Zhengyu He
标识
DOI:10.48550/arxiv.2212.04197
摘要
A number of trusted execution environments (TEEs) have been proposed by both academia and industry. However, most of them require specific hardware or firmware changes and are bound to specific hardware vendors (such as Intel, AMD, ARM, and IBM). In this paper, we propose HyperEnclave, an open and cross-platform process-based TEE that relies on the widely-available virtualization extension to create the isolated execution environment. In particular, HyperEnclave is designed to support the flexible enclave operation modes to fulfill the security and performance demands under various enclave workloads. We provide the enclave SDK to run existing SGX programs on HyperEnclave with little or no source code changes. We have implemented HyperEnclave on commodity AMD servers and deployed the system in a world-leading FinTech company to support real-world privacy-preserving computations. The evaluation on both micro-benchmarks and application benchmarks shows the design of HyperEnclave introduces only a small overhead.
科研通智能强力驱动
Strongly Powered by AbleSci AI