Adaptive and Efficient Dynamic Memory Management for Hardware Enclaves

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Dhanraj, Vijay, Chawla, Harpreet Singh, Zhang, Tao, Manila, Daniel, Schneider, Eric Thomas, Fu, Erica, Vij, Mona, Tsai, Chia-Che, Porter, Donald E.
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915315153108992
author Dhanraj, Vijay
Chawla, Harpreet Singh
Zhang, Tao
Manila, Daniel
Schneider, Eric Thomas
Fu, Erica
Vij, Mona
Tsai, Chia-Che
Porter, Donald E.
author_facet Dhanraj, Vijay
Chawla, Harpreet Singh
Zhang, Tao
Manila, Daniel
Schneider, Eric Thomas
Fu, Erica
Vij, Mona
Tsai, Chia-Che
Porter, Donald E.
contents The second version of Intel Software Guard Extensions (Intel SGX), or SGX2, adds dynamic management of enclave memory and threads. The first version required the address space and thread counts to be fixed before execution. The Enclave Dynamic Memory Management (EDMM) feature of SGX2 has the potential to lower launch times and overall execution time. Despite reducing the enclave loading time by 28--93%, straightforward EDMM adoption strategies actually slow execution time down by as much as 58%. Using the Gramine library OS as a representative enclave runtime environment, this paper shows how to recover EDMM performance. The paper explains how implementing mutual distrust between the OS and enclave increases the cost of modifying page mappings. The paper then describes and evaluates a series of optimizations on application benchmarks, showing that these optimizations effectively eliminate the overheads of EDMM while retaining EDMM's performance and flexibility gains.
format Preprint
id arxiv_https___arxiv_org_abs_2504_16251
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Adaptive and Efficient Dynamic Memory Management for Hardware Enclaves
Dhanraj, Vijay
Chawla, Harpreet Singh
Zhang, Tao
Manila, Daniel
Schneider, Eric Thomas
Fu, Erica
Vij, Mona
Tsai, Chia-Che
Porter, Donald E.
Operating Systems
Cryptography and Security
The second version of Intel Software Guard Extensions (Intel SGX), or SGX2, adds dynamic management of enclave memory and threads. The first version required the address space and thread counts to be fixed before execution. The Enclave Dynamic Memory Management (EDMM) feature of SGX2 has the potential to lower launch times and overall execution time. Despite reducing the enclave loading time by 28--93%, straightforward EDMM adoption strategies actually slow execution time down by as much as 58%. Using the Gramine library OS as a representative enclave runtime environment, this paper shows how to recover EDMM performance. The paper explains how implementing mutual distrust between the OS and enclave increases the cost of modifying page mappings. The paper then describes and evaluates a series of optimizations on application benchmarks, showing that these optimizations effectively eliminate the overheads of EDMM while retaining EDMM's performance and flexibility gains.
title Adaptive and Efficient Dynamic Memory Management for Hardware Enclaves
topic Operating Systems
Cryptography and Security
url https://arxiv.org/abs/2504.16251