Proceedings 2021 Network and Distributed System Security Symposium 2021
DOI: 10.14722/ndss.2021.24057
|View full text |Cite
|
Sign up to set email alerts
|

CHANCEL: Efficient Multi-client Isolation Under Adversarial Programs

Abstract: Intel SGX aims to provide the confidentiality of user data on untrusted cloud machines. However, applications that process confidential user data may contain bugs that leak information or be programmed maliciously to collect user data. Existing research that attempts to solve this problem does not consider multi-client isolation in a single enclave. We show that by not supporting such in-enclave isolation, they incur considerable slowdown when concurrently processing multiple clients in different enclave proce… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

0
14
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
6

Relationship

0
6

Authors

Journals

citations
Cited by 12 publications
(14 citation statements)
references
References 43 publications
0
14
0
Order By: Relevance
“…In addition to the increased TCB, the memory access occurring in the enclave must be verified by instrumented instructions, causing extra performance costs. A recent study [28] reports that the software-based confinement incurs a slowdown of an average of 12.43%, up to 24.89% compared to native execution because it requires 23.52% more instructions.…”
Section: Bi-directional Isolation With Enclavementioning
confidence: 99%
See 4 more Smart Citations
“…In addition to the increased TCB, the memory access occurring in the enclave must be verified by instrumented instructions, causing extra performance costs. A recent study [28] reports that the software-based confinement incurs a slowdown of an average of 12.43%, up to 24.89% compared to native execution because it requires 23.52% more instructions.…”
Section: Bi-directional Isolation With Enclavementioning
confidence: 99%
“…Similar to STOCKADE, Ryoan decomposed a cloud application into distributed enclaves with the software sandboxing and SW-encrypted channels. Chancel [28] proposes multi-client software fault isolation through binary instrumentation and read-only shared memory between threads. It supports multiple isolated threads within an enclave.…”
Section: Comparison To the Prior Workmentioning
confidence: 99%
See 3 more Smart Citations