SEmigrate: Optimizing Data Protection with VM Introspection

Shuhei Horio, Kouta Takahashi, Kenichi Kourai · 2023

Recently, virtual machines (VMs) with a large amount of memory are widely used. Since it is often difficult to migrate such a large-memory VM to one large destination host, split migration divides the memory of a VM into small fragments and transfers them to multiple destination hosts. The migrated VM exchanges its memory data between the hosts using remote paging. To prevent information leakage from and tampering with the memory data in an untrusted environment, memory encryption and integrity checking can be used. However, the overhead of such data protection affects the performance of the hosts and the VM more largely in faster networks. This paper proposes SEmigrate for optimizing data protection in split migration and remote paging. SEmigrate avoids decrypting memory data and integrity checking at most of the destination hosts to reduce the protection overhead and completely prevent information leakage. Also, it can selectively encrypt only sensitive memory data and check the integrity of only important memory data by analyzing the memory of the guest operating system and applications in a VM. SEmigrate could reduce the time for data-protected split migration by up to 43% and improve the performance of migrated VMs by up to 19% in 100 Gigabit Ethernet.

Read the paper · More papers on PaperTik