COMURICE: Closing Source Code Leakage in Cloud-Based Compiling via Enclave

Dahan Pan, Jianqiang Wang, Yingpeng Chen, Donghui Yu, Wenbo Yang, Yuanyuan Zhang · 2024

Cloud-native-based software development is in trend now. The end-users use the cloud services to save the local computation resources for other intensive tasks. Compiling is one of the vital required services. The compiling-on-the-cloud service like CloudCompiling or CityCloud requires the user to upload their source code for online compiling. However, the latest online compiling service can neither protect the users' source code privacy nor prove the integrity of the whole compiling process. To fill this gap, we designed COMURICEto provide a user-transparent, secure compiling service employing the trusted execution environment (TEE) to enforce security by blocking all the attempts in code or data theft during the compiling procedure. COMURICEleverages the hardware security feature of TEE to prevent the compiling process from malicious access and modification while encrypting the communication channel to protect the integrity and privacy of the source code. The challenges in realizing COMURICElie in porting a fully functional compiler such as GCC or LLVM and designing an efficient compiling service to minimize the performance lag brought by confidential computing. According to the characteristics of the compiling process, it consists of several routines, pre-processing, compiling/obfuscation, and linking. The division of the routines requires multiple enclaves to run simultaneously. In the experiment, we compare COMURICE'Scompiling service with nativeLLVM, SCONELLVM, and GrapheneLLVM. From a performance perspective, COMURICEpays a fair cost for security. Generally, a project compiling with COMURICEsuffers 1–2 times more performance loss than nativeLLVM. Compared to other confidential compiling techniques like GrapheneLLVM or SCONELLVM, COMURICEis up to 20 times faster when compiling the same projects.

Read the paper · More papers on PaperTik