4 ms·
I'm not an OS person, so forgive me if this is a stupid question: Lots of people are excited about Intel SGX and similar things. Are there any interesting ways
by swordswinger12 10y ago
I'm not an OS person, so forgive me if this is a stupid question: Lots of people are excited about Intel SGX and similar things. Are there any interesting ways people are thinking about combining, like, Docker containers with SGX enclaves and such? One could imagine (e.g.) using remote attestation to verify an entire container image.
- geofft 10y agoIt's definitely not a stupid question. I think you can't do it very well because a contained process is just a process on the host system, albeit with a few things changed (like what network devices it sees), and it's pretty hard to make an enclave as big as an entire OS process. However, see VMware's Overshadow paper for a pretty clever system that lets you run a verified process inside an untrusted kernel instide a trusted hypervisor: https://labs.vmware.com/academic/publications/overshadow https://labs.vmware.com/academic/publications/overshadow You might be able to do something similar.
- wmf 10y agoYeah, it's called SCONE: https://www.usenix.org/conference/osdi16/technical-sessions/presentation/arnautov https://www.usenix.org/conference/osdi16/technical-sessions/... It's pretty kludgey due to SGX limitations like not supporting fork().