arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.03849cs.CRcs.OS

NACRE:通过原生架构支持重新思考机密容器

NACRE: Rethinking Confidential Containers through Native Architectural Support

  • Defense Institute of Information Engineering, CAS(中国科学技术大学信息工程研究所)
  • University of Chinese Academy of Sciences(中国科学院大学)
  • Nankai University(南开大学)

机构由 AI 辅助整理,请以论文原文为准。

Linke Song, Wenhao Wang, Weijie Liu, Rui Hou

AI总结:

本文提出一种用于RISC-V的软硬件协同设计NACRE,将主机资源管理与受保护状态访问权限分离,实现原生机密容器,原型性能与runc基准接近,为容器机密性提供新架构方案。

AI中文摘要:

Linux容器通过共享主机内核实现了高密度和快速的生命周期操作,但这种设计也让被入侵的主机能够检查或修改容器状态。现有的机密计算系统会保护一个飞地地址空间或整个客户操作系统,而近期的容器粒度系统仍会添加一个独立的保护上下文,这些抽象并未将主机管理的Linux进程的动态组作为架构保护单元。本文提出NACRE,一种用于原生机密容器的RISC-V软硬件协同设计,其核心洞见是将主机管理资源的权限与访问或提交受保护状态的权限分离。硬件识别的容器身份会将受保护的陷阱定向到隔离的S模式代理,而M模式监视器则提交安全敏感的身份、映射和页面转换。该代理在不更改satp的情况下将服务委托给主机Linux,既不访问私有字节也不修改受保护状态的服务还可避免进入M模式。我们通过扩展QEMU、OpenSBI、Linux、可信代理和runc对NACRE进行原型设计,该原型实现了单容器私有内存基础,并覆盖了启动、故障、写时复制(fork/COW)、用户访问和拆除路径。在5项lmbench系统调用和管道指标上,三次运行的均值与runc原始基准的差值保持在3.5%以内;在8项nginx对象大小的均值等权重下,总吞吐量降低了1.9%。

英文摘要:

Linux containers achieve high density and fast lifecycle operations by sharing the host kernel, but this design also lets a compromised host inspect or modify container state. Existing confidential-computing systems protect an enclave address space or an entire guest operating system, while recent container-granularity systems still add a separate protection context. These abstractions do not make a dynamic group of host-managed Linux processes the architectural protection unit. This paper presents NACRE, a RISC-V hardware-software co-design for native confidential containers. Its key insight is to separate the host's authority to manage resources from its authority to access or commit protected state. Hardware-recognized container identities direct protected traps to an isolated S-mode agent, while an M-mode monitor commits security- sensitive identity, mapping, and page transitions. The agent delegates services to host Linux without changing satp; services that neither access private bytes nor modify protected state also avoid M-mode. We prototype NACRE by extending QEMU, OpenSBI, Linux, a trusted agent, and runc. The prototype implements the single-container private-memory substrate and covered launch, fault, fork/COW, user-access, and teardown paths. Across five lmbench syscall and pipe metrics, the three-run means remain within 3.5% of the runc-origin baseline. With the eight nginx object-size means weighted equally, aggregate throughput is 1.9% lower.

补充信息

↑