Scaling Intel® Software Guard Extensions Applications with Intel® SGX Card

被引:4
|
作者
Chakrabarti, Somnath [1 ]
Hoekstra, Matthew [1 ]
Kuvaiskii, Dmitrii [1 ]
Vij, Mona [1 ]
机构
[1] Intel Labs, Santa Clara, CA 95054 USA
关键词
Intel (R) Software Guard Extensions; Intel (R) SGX Card;
D O I
10.1145/3337167.3337173
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud computing revolutionized the way internet-scale services are deployed and scaled. However, general security concerns and protecting business critical data are still major factors holding companies back from moving their IT infrastructure to the cloud. Intel (R) Software Guard Extensions (Intel (R) SGX) technology provides a hardware enforced trusted execution environment specifically developed to compute on confidential data in untrusted public clouds. To date, Intel SGX is available only on single-socket platforms and its secure memory limited to 128 MB. This paper describes how the Intel SGX Card makes the Intel SGX technology available on dual-socket server platforms today and easily integrated into existing data center infrastructure. Also, with software enabling, there is potential for applications to scale-out across the cards's three Intel (R) Xeon (R) E3 processors for additional secure memory. We propose four software architectures to efficiently utilize the card's resources and present use cases that benefit from Intel SGX card based deployments.
引用
收藏
页数:9
相关论文
共 50 条
  • [31] SCONE: Secure Linux Containers with Intel SGX
    Arnautov, Sergei
    Trach, Bohdan
    Gregor, Franz
    Knauth, Thomas
    Martin, Andre
    Priebe, Christian
    Lind, Joshua
    Muthukumaran, Divya
    O'Keeffe, Dan
    Stillwell, Mark L.
    Goltzsche, David
    Eyers, David
    Kapitza, Rudiger
    Pietzuch, Peter
    Fetzer, Christof
    [J]. PROCEEDINGS OF OSDI'16: 12TH USENIX SYMPOSIUM ON OPERATING SYSTEMS DESIGN AND IMPLEMENTATION, 2016, : 689 - 703
  • [32] Protecting OpenFlow Flow Tables with Intel SGX
    Paladi, Nicolae
    Svenningsson, Jakob
    Medina, Jorge
    Arlos, Patrik
    [J]. PROCEEDINGS OF THE 2019 ACM SIGCOMM CONFERENCE POSTERS AND DEMOS (SIGCOMM '19), 2019, : 146 - 147
  • [33] Glamdring: Automatic Application Partitioning for Intel SGX
    Lind, Joshua
    Priebe, Christian
    Muthukumaran, Divya
    O'Keeffe, Dan
    Aublin, Pierre-Louis
    Kelbert, Florian
    Reiher, Tobias
    Goltzsche, David
    Eyers, David
    Kapitza, Rudiger
    Fetzer, Christof
    Pietzuch, Peter
    [J]. 2017 USENIX ANNUAL TECHNICAL CONFERENCE (USENIX ATC '17), 2017, : 285 - 298
  • [34] Obfuscating Program Control Flow with Intel SGX
    Wang, Yongzhi
    Shen, Yulong
    Cheng, Ke
    Yang, Yibo
    Su, Cuicui
    Faree, Anter
    [J]. PROCEEDINGS 2018 IEEE/ACM 40TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING - COMPANION (ICSE-COMPANION, 2018, : 321 - 322
  • [35] Hardening Application Security using Intel SGX
    Plauth, Max
    Teschke, Fredrik
    Richter, Daniel
    Polze, Andreas
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY (QRS 2018), 2018, : 375 - 380
  • [36] OBFUSCURO: A Commodity Obfuscation Engine on Intel SGX
    Ahmad, Adil
    Joe, Byunggill
    Xiao, Yuan
    Zhang, Yinqian
    Shin, Insik
    Lee, Byoungyoung
    [J]. 26TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2019), 2019,
  • [37] Mitigating Password Database Breaches with Intel SGX
    Brekalo, Helena
    Strackx, Raoul
    Piessens, Frank
    [J]. SYSTEX 2016: 1ST WORKSHOP ON SYSTEM SOFTWARE FOR TRUSTED EXECUTION, 2016,
  • [38] A Comprehensive Trusted Runtime for WebAssembly With Intel SGX
    Menetrey, James
    Pasin, Marcelo
    Felber, Pascal
    Schiavoni, Valerio
    Mazzeo, Giovanni
    Hollum, Arne
    Vaydia, Darshan
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 3562 - 3579
  • [39] CFHider: Control Flow Obfuscation with Intel SGX
    Wang, Yongzhi
    Shen, Yulong
    Su, Cuicui
    Cheng, Ke
    Yang, Yibo
    Faree, Anter
    Liu, Yao
    [J]. IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2019), 2019, : 541 - 549
  • [40] UniGuard: Protecting Unikernels using Intel SGX
    Sfyrakis, Ioannis
    Gross, Thomas
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E 2018), 2018, : 99 - 105