SGXPool: Improving the performance of enclave creation in the cloud
Dingding Li, Ronghua Lin, Lijie Tang, Hai Liu, Yong Tang · Transactions on Emerging Telecommunications Technologies · 2019
Abstract Deploying user data or programs in cloud risks divulging their privacy because the cloud‐side supervisors, such as system administrators, can leverage the higher privilege to snoop the user data. Based on the trusted execution environment (TEE) technology, Intel Software Guard eXtension (SGX) is a practical remedy to user privacy, which employs hardware‐assisted enclave to wrap the sensitive data, preventing them from the disclosure. However, the application performance is hurt due to the CPU‐expensive and frequent operations on the enclave creation and destruction. In this paper, we propose SGXPool, an application‐level framework of resource management to relieve the above issue. SGXPool first uses a preallocated resource pool to assign/revoke the enclave on demand and avoids its cost of dynamical creation and destruction. Then, SGXPool utilizes another resource pool to constrain the threading overhead such as thread initialization, scheduling, and destruction. In addition, SGXPool exposes the simple and clear interface, allowing users or programmers to apply SGXPool without any intrusive modifications on the original SGX application. We implement SGXPool in the typical web servers which use the multithreading to handle the concurrent user requests. The evaluation results show that SGXPool can improve the performance of the original multithreading system up to 19 times. Meanwhile, the original security of SGX is maintained.