• Cite Icon2
  • https://doi.org/10.1145/2818000.2818044Copy DOI Icon

Privacy-preserving Virtual Machine

  • Dec 7, 2015
  • Tianlin Li +3 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Cloud computing systems routinely process users' confidential data, but the underlying virtualization software in use today is not constructed to minimize the exposure of such data. For instance, virtual machine (VM) checkpointing can drastically prolong the lifetime and vulnerability of confidential data without users' knowledge by storing such data as part of a persistent snapshot. A key requirement for minimizing the exposure of any data is the ability to cleanly isolate such data for either exclusion or processing. Traditional mechanisms for memory taint tracking are expensive whereas those for isolating application footprint in VM-based sandboxes are not transparent. In this paper, we propose a transparent and lightweight mechanism for isolating a confidential application's memory footprint in a VM. The key idea is for a parent VM to spawn a child VM, called a Privacy-preserving Virtual Machine (PPVM) within which the confidential application executes. Hypervisor features, such as VM checkpointing, that need to exclude the memory of a confidential application can safely ignore the child VM's memory footprint. Alternatively, features such as checkpoint encryption or malware tracking can operate only on the child VM's memory. We implement memory isolation for PPVM through a lightweight VM fork operation that uses copy-on-write to reduce the memory and filesystem overhead of the PPVM. Transparency is achieved through a confidential shell that allows the parent VM to spawn the confidential application in the PPVM and exercise control over it during runtime. We demonstrate the effectiveness of PPVM through its use with VM checkpointing, which can safely checkpoint the parent VM while excluding or encrypting the associated PPVM. We show that our PPVM implementation achieves effective memory isolation with low overheads on memory, CPU, and network performance.

Similar Papers
  • Conference Article
  • Citations18

SPARC

  • Oct 17, 2011
  • Mikhail I Gofman +3
  • Conference Article
  • Citations24

Secure MMU: Architectural support for memory isolation among virtual machines

  • Jun 01, 2011
  • Seongwook Jin +1
  • Conference Article
  • Citations8

Optimize Performance of Virtual Machine Checkpointing via Memory Exclusion

  • Aug 01, 2009
  • Haikun Liu +2
  • Research Article
  • Citations2

HA-VMSI

  • Apr 08, 2017
  • ACM SIGPLAN Notices
  • Min Zhu +3
  • Conference Article
  • Citations3

Quick Eviction of Virtual Machines through Proactive Snapshots

  • Sep 01, 2016
  • Dinuni Fernando +6
  • Conference Article
  • Citations17

Dynamic Memory Pressure Aware Ballooning

  • Oct 05, 2015
  • Jinchun Kim +3
  • Conference Article
  • Citations22

Utilizing Memory Content Similarity for Improving the Performance of Replicated Virtual Machines

  • Dec 01, 2011
  • B Gerofi +2
  • Conference Article
  • Citations262

CloudNet

  • Mar 09, 2011
  • Timothy Wood +3
  • Research Article
  • Citations5

Scalable and efficient workload hotspot detection in virtualized environment

  • May 27, 2014
  • Cluster Computing
  • Zhou Lei +5
  • Conference Article
  • Citations7

Multi-processor architectural support for protecting virtual machine privacy in untrusted cloud environment

  • May 14, 2013
  • Yuanfeng Wen +6
  • PDF
  • Research Article
  • Citations6

A Virtual Network Resource Allocation Framework Based on SR-IOV

  • Jan 02, 2019
  • Applied Sciences
  • Zhiyong Ye +2
  • Conference Article

The Effect of Resource Allocation and System Events on VM Consolidation

  • Sep 01, 2017
  • Maruf Ahmed +1
  • Conference Article
  • Citations1

A CPU Overhead-Aware VM Placement Algorithm for Network Bandwidth Guarantee in Virtualized Data Centers

  • Sep 01, 2015
  • Kwonyong Lee +1
  • Research Article
  • Citations58

XHive: Efficient Cooperative Caching for Virtual Machines

  • Jan 01, 2011
  • IEEE Transactions on Computers
  • Hwanju Kim +2
  • Conference Article
  • Citations23

VMPatrol: dynamic and automated QoS for virtual machine migrations

  • Oct 22, 2012
  • Vijay Mann +3
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.