Spons & Shields: practical isolation for trusted execution

Vasily A. Sartakov, Dan O’Keeffe, David M. Eyers, Lluís Vilanova, Peter R. Pietzuch · 2021

Trusted execution environments (TEEs) promise a cost-effective, “lift-and-shift” solution for deploying security-sensitive applications in untrusted clouds. For this, they must support rich, multi-component applications, but a large trusted computing base (TCB) inside the TEE risks that attackers can compromise application security. Fine-grained compartmentalisation can increase security through defense-in-depth, but current solutions either run all software components unprotected in the same TEE, lack efficient shared memory support, or isolate application processes using separate TEEs, impacting performance and compatibility.

Read the paper · More papers on PaperTik