A Comprehensive Trusted Runtime for WebAssembly With Intel SGX

Jämes Ménétrey, Marcelo Pasin, Pascal A. Felber, Valerio Schiavoni, Giovanni Mazzeo, Arne Hollum, Darshan Vaydia · IEEE Transactions on Dependable and Secure Computing · 2023

In real-world scenarios, trusted execution environments (TEEs) frequently host applications that lack the trust of the infrastructure provider, as well as data owners who have specifically outsourced their data for remote processing. We presentTwine, a trusted runtime for running WebAssembly-compiled applications within TEEs, establishing a two-way sandbox.Twineleverages memory safety guarantees of WebAssembly (Wasm) and abstracts the complexity of TEEs, empowering the execution of legacy and language-agnostic applications. It extends the standard WebAssembly system interface (WASI), providing controlled OS services, focusing on I/O. Additionally, through built-in TEE mechanisms,Twinedelivers attestation capabilities to ensure the integrity of the runtime and the OS services supplied to the application. We evaluate its performance using general-purpose benchmarks and real-world applications, showing it compares on par with state-of-the-art solutions. A case study involving fintech companyCredorareveals thatTwinecan be deployed in production with reasonable performance trade-offs, ranging from a 0.7× slowdown to a 1.17× speedup compared to native run time. Finally, we identify performance improvement through library optimisation, showcasing one such adjustment that leads up to$4.1\times$speedup.Twineis open-source and has been upstreamed into the original Wasm runtime, WAMR.

Read the paper · More papers on PaperTik