{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T05:08:33Z","timestamp":1782968913171,"version":"3.54.5"},"reference-count":46,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2019,3,26]],"date-time":"2019-03-26T00:00:00Z","timestamp":1553558400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Proc. ACM Meas. Anal. Comput. Syst."],"published-print":{"date-parts":[[2019,3,26]]},"abstract":"<jats:p>Intel SGX has attracted much attention from academia and is already powering commercial applications. Cloud providers have also started implementing SGX in their cloud offerings. Research efforts on Intel SGX so far have mainly concentrated on its security and programmability. However, no work has studied in detail the performance degradation caused by SGX in virtualized systems. Such settings are particularly important, considering that virtualization is the de facto building block of cloud infrastructure, yet often comes with a performance impact. This paper presents for the first time a detailed performance analysis of Intel SGX in a virtualized system in comparison with a bare-metal system. Based on our findings, we identify several optimization strategies that would improve the performance of Intel SGX on such systems.<\/jats:p>","DOI":"10.1145\/3322205.3311076","type":"journal-article","created":{"date-parts":[[2020,3,26]],"date-time":"2020-03-26T13:12:37Z","timestamp":1585228357000},"page":"1-21","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":24,"title":["Everything You Should Know About Intel SGX Performance on Virtualized Systems"],"prefix":"10.1145","volume":"3","author":[{"given":"Tu","family":"Dinh Ngoc","sequence":"first","affiliation":[{"name":"IRIT, Toulouse, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bao","family":"Bui","sequence":"additional","affiliation":[{"name":"IRIT, Toulouse, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Stella","family":"Bitchebe","sequence":"additional","affiliation":[{"name":"IRIT, Toulouse, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alain","family":"Tchana","sequence":"additional","affiliation":[{"name":"I3S, Valbone, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Valerio","family":"Schiavoni","sequence":"additional","affiliation":[{"name":"Universit\u00e9 de Neuch\u00e2tel, Neuch\u00e2tel, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pascal","family":"Felber","sequence":"additional","affiliation":[{"name":"Universit\u00e9 de Neuch\u00e2tel, Neuch\u00e2tel, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Daniel","family":"Hagimont","sequence":"additional","affiliation":[{"name":"IRIT, Toulouse, France"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2019,3,26]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Proceedings of the 2nd international workshop on hardware and architectural support for security and privacy","volume":"13","author":"Anati Ittai","year":"2013","unstructured":"Ittai Anati , Shay Gueron , Simon Johnson , and Vincent Scarlata . 2013 . Innovative technology for CPU based attestation and sealing . In Proceedings of the 2nd international workshop on hardware and architectural support for security and privacy , Vol. 13 . ACM New York, NY, USA. Ittai Anati, Shay Gueron, Simon Johnson, and Vincent Scarlata. 2013. Innovative technology for CPU based attestation and sealing. In Proceedings of the 2nd international workshop on hardware and architectural support for security and privacy, Vol. 13. ACM New York, NY, USA."},{"key":"e_1_2_1_2_1","first-page":"689","article-title":"SCONE: Secure Linux Containers with Intel SGX","volume":"16","author":"Arnautov Sergei","year":"2016","unstructured":"Sergei Arnautov , Bohdan Trach , Franz Gregor , Thomas Knauth , Andre Martin , Christian Priebe , Joshua Lind , Divya Muthukumaran , Dan O'Keeffe , Mark Stillwell , 2016 . SCONE: Secure Linux Containers with Intel SGX .. In OSDI , Vol. 16. 689 -- 703 . Sergei Arnautov, Bohdan Trach, Franz Gregor, Thomas Knauth, Andre Martin, Christian Priebe, Joshua Lind, Divya Muthukumaran, Dan O'Keeffe, Mark Stillwell, et almbox. 2016. SCONE: Secure Linux Containers with Intel SGX.. In OSDI, Vol. 16. 689--703.","journal-title":"OSDI"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1353534.1346286"},{"key":"e_1_2_1_5_1","volume-title":"Performance evaluation of Intel EPT hardware assist. VMware","author":"Bhatia Nikhil","year":"2009","unstructured":"Nikhil Bhatia . 2009. Performance evaluation of Intel EPT hardware assist. VMware , Inc ( 2009 ). Nikhil Bhatia. 2009. Performance evaluation of Intel EPT hardware assist. VMware, Inc (2009)."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/2988336.2988350"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3092627.3092634"},{"key":"e_1_2_1_8_1","volume-title":"Graphene-SGX: A Practical Library OS for Unmodified Applications on SGX. In 2017 USENIX Annual Technical Conference (USENIX ATC 17)","author":"Tsai Chia","year":"2017","unstructured":"Chia che Tsai , Donald E. Porter , and Mona Vij . 2017 . Graphene-SGX: A Practical Library OS for Unmodified Applications on SGX. In 2017 USENIX Annual Technical Conference (USENIX ATC 17) . USENIX Association, Santa Clara, CA, 645--658. https:\/\/www.usenix.org\/conference\/atc17\/technical-sessions\/presentation\/tsai Chia che Tsai, Donald E. Porter, and Mona Vij. 2017. Graphene-SGX: A Practical Library OS for Unmodified Applications on SGX. In 2017 USENIX Annual Technical Conference (USENIX ATC 17) . USENIX Association, Santa Clara, CA, 645--658. https:\/\/www.usenix.org\/conference\/atc17\/technical-sessions\/presentation\/tsai"},{"key":"e_1_2_1_9_1","volume-title":"SgxPectre Attacks: Stealing Intel Secrets from SGX Enclaves via Speculative Execution . arXiv preprint arXiv:1802.09085","author":"Chen Guoxing","year":"2018","unstructured":"Guoxing Chen , Sanchuan Chen , Yuan Xiao , Yinqian Zhang , Zhiqiang Lin , and Ten H Lai . 2018. SgxPectre Attacks: Stealing Intel Secrets from SGX Enclaves via Speculative Execution . arXiv preprint arXiv:1802.09085 ( 2018 ). Guoxing Chen, Sanchuan Chen, Yuan Xiao, Yinqian Zhang, Zhiqiang Lin, and Ten H Lai. 2018. SgxPectre Attacks: Stealing Intel Secrets from SGX Enclaves via Speculative Execution . arXiv preprint arXiv:1802.09085 (2018)."},{"key":"e_1_2_1_10_1","unstructured":"Sean Christopherson. 2017. KVM: vmx: add support for SGX Launch Control. https:\/\/github.com\/intel\/kvm-sgx\/commit\/e9a065d3c1773ad72bfb28b6dad4c433f392eda8 .  Sean Christopherson. 2017. KVM: vmx: add support for SGX Launch Control. https:\/\/github.com\/intel\/kvm-sgx\/commit\/e9a065d3c1773ad72bfb28b6dad4c433f392eda8 ."},{"key":"e_1_2_1_11_1","unstructured":"Intel Corporation. 2018a. Intel Linux SGX SDK v2.2 -- Switchless Calls . https:\/\/download.01.org\/intel-sgx\/linux-2.2\/docs\/Intel_SGX_Developer_Reference_Linux_2.2_Open_Source.pdf .  Intel Corporation. 2018a. Intel Linux SGX SDK v2.2 -- Switchless Calls . https:\/\/download.01.org\/intel-sgx\/linux-2.2\/docs\/Intel_SGX_Developer_Reference_Linux_2.2_Open_Source.pdf ."},{"key":"e_1_2_1_12_1","unstructured":"Intel Corporation. 2018b. L1 Terminal Fault . https:\/\/software.intel.com\/security-software-guidance\/software-guidance\/l1-terminal-fault .  Intel Corporation. 2018b. L1 Terminal Fault . https:\/\/software.intel.com\/security-software-guidance\/software-guidance\/l1-terminal-fault ."},{"key":"e_1_2_1_13_1","first-page":"86","article-title":"Intel SGX Explained","volume":"2016","author":"Costan Victor","year":"2016","unstructured":"Victor Costan and Srinivas Devadas . 2016 . Intel SGX Explained . IACR Cryptology ePrint Archive , Vol. 2016 (2016), 86 . Victor Costan and Srinivas Devadas. 2016. Intel SGX Explained. IACR Cryptology ePrint Archive , Vol. 2016 (2016), 86.","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_2_1_14_1","unstructured":"Tu Dinh Ngoc. 2018. SGX benchmark source code. https:\/\/github.com\/sgxbench\/sgxbench\/releases .  Tu Dinh Ngoc. 2018. SGX benchmark source code. https:\/\/github.com\/sgxbench\/sgxbench\/releases ."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1203224"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2016.67"},{"key":"e_1_2_1_17_1","unstructured":"Google. 2018. Asylo: an open-source framework for confidential computing . https:\/\/cloudplatform.googleblog.com\/2018\/05\/Introducing-Asylo-an-open-source-framework-for-confidential-computing.html .  Google. 2018. Asylo: an open-source framework for confidential computing . https:\/\/cloudplatform.googleblog.com\/2018\/05\/Introducing-Asylo-an-open-source-framework-for-confidential-computing.html ."},{"key":"e_1_2_1_18_1","volume-title":"Dynamics of a Trusted Platform: A building block approach","author":"Grawrock David","unstructured":"David Grawrock . 2009. Dynamics of a Trusted Platform: A building block approach . Intel Press . David Grawrock. 2009. Dynamics of a Trusted Platform: A building block approach .Intel Press."},{"key":"e_1_2_1_19_1","unstructured":"Trusted Computing Group. 2007. Design Principles Specification Version 1.2 Level 2 Revision 103 Part 1.  Trusted Computing Group. 2007. Design Principles Specification Version 1.2 Level 2 Revision 103 Part 1."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2016.124"},{"key":"e_1_2_1_21_1","unstructured":"Danny Harnik and Eliad Tsfadia. 2017. Impressions of Intel SGX performance. https:\/\/medium.com\/@danny_harnik\/22442093595a .  Danny Harnik and Eliad Tsfadia. 2017. Impressions of Intel SGX performance. https:\/\/medium.com\/@danny_harnik\/22442093595a ."},{"key":"e_1_2_1_22_1","unstructured":"IBM. 2018. Data-in-use protection on IBM Cloud using Intel SGX . https:\/\/www.ibm.com\/blogs\/bluemix\/2018\/05\/data-use-protection-ibm-cloud-using-intel-sgx\/.  IBM. 2018. Data-in-use protection on IBM Cloud using Intel SGX . https:\/\/www.ibm.com\/blogs\/bluemix\/2018\/05\/data-use-protection-ibm-cloud-using-intel-sgx\/."},{"key":"e_1_2_1_23_1","unstructured":"Intel. 2018. Intel Software Development Manual . https:\/\/software.intel.com\/en-us\/articles\/intel-sdm .  Intel. 2018. Intel Software Development Manual . https:\/\/software.intel.com\/en-us\/articles\/intel-sdm ."},{"key":"e_1_2_1_24_1","unstructured":"Intel Corporation. {n. d.} a. Intel Software Guard Extensions SDK . https:\/\/software.intel.com\/en-us\/sgx-sdk .  Intel Corporation. {n. d.} a. Intel Software Guard Extensions SDK . https:\/\/software.intel.com\/en-us\/sgx-sdk ."},{"key":"e_1_2_1_25_1","unstructured":"Intel Corporation. {n. d.} b. Intel Software Guard Extensions SDK for Linux . https:\/\/01.org\/intel-software-guard-extensions .  Intel Corporation. {n. d.} b. Intel Software Guard Extensions SDK for Linux . https:\/\/01.org\/intel-software-guard-extensions ."},{"key":"e_1_2_1_26_1","unstructured":"Intel Corporation. {n. d.} c. SGX Virtualization. https:\/\/01.org\/intel-software-guard-extensions\/sgx-virtualization .  Intel Corporation. {n. d.} c. SGX Virtualization. https:\/\/01.org\/intel-software-guard-extensions\/sgx-virtualization ."},{"key":"e_1_2_1_27_1","unstructured":"Intel Corporation. 2017a. Intel and NeuLion Bring Secure 4K UHD Sports Streaming to Computers. https:\/\/newsroom.intel.com\/news\/intel-neulion-bring-secure-4k-uhd-sports-streaming-computers\/.  Intel Corporation. 2017a. Intel and NeuLion Bring Secure 4K UHD Sports Streaming to Computers. https:\/\/newsroom.intel.com\/news\/intel-neulion-bring-secure-4k-uhd-sports-streaming-computers\/."},{"key":"e_1_2_1_28_1","unstructured":"Intel Corporation. 2017b. Intel Software Guard Extensions SDK for Linux OS. https:\/\/download.01.org\/intel-sgx\/linux-2.0\/docs\/Intel_SGX_Installation_Guide_Linux_2.0_Open_Source.pdf  Intel Corporation. 2017b. Intel Software Guard Extensions SDK for Linux OS. https:\/\/download.01.org\/intel-sgx\/linux-2.0\/docs\/Intel_SGX_Installation_Guide_Linux_2.0_Open_Source.pdf"},{"key":"e_1_2_1_29_1","unstructured":"International Organization for Standardization. 2015. ISO\/IEC 11889--1:2015 .  International Organization for Standardization. 2015. ISO\/IEC 11889--1:2015 ."},{"key":"e_1_2_1_30_1","volume-title":"AMD memory encryption. White paper","author":"Kaplan David","year":"2016","unstructured":"David Kaplan , Jeremy Powell , and Tom Woller . 2016. AMD memory encryption. White paper ( 2016 ). David Kaplan, Jeremy Powell, and Tom Woller. 2016. AMD memory encryption. White paper (2016)."},{"key":"e_1_2_1_31_1","unstructured":"Alexey Kopytov. {n. d.}.  Alexey Kopytov. {n. d.}."},{"key":"e_1_2_1_32_1","volume-title":"ECRYPT Workshop, CRASH-CRyptographic Advances in Secure Hardware .","author":"Kursawe Klaus","year":"2005","unstructured":"Klaus Kursawe , Dries Schellekens , and Bart Preneel . 2005 . Analyzing trusted platform communication . In ECRYPT Workshop, CRASH-CRyptographic Advances in Secure Hardware . Klaus Kursawe, Dries Schellekens, and Bart Preneel. 2005. Analyzing trusted platform communication. In ECRYPT Workshop, CRASH-CRyptographic Advances in Secure Hardware ."},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/AINA.2017.79"},{"key":"e_1_2_1_34_1","volume-title":"Proceedings of the 2017 USENIX Conference on Usenix Annual Technical Conference (USENIX ATC '17). USENIX Association","author":"Lind Joshua","year":"2017","unstructured":"Joshua Lind , Christian Priebe , Divya Muthukumaran , Dan O'Keeffe , Pierre-Louis Aublin , Florian Kelbert , Tobias Reiher , David Goltzsche , David Eyers , R\u00fcdiger Kapitza , Christof Fetzer , and Peter Pietzuch . 2017 . Glamdring: Automatic Application Partitioning for Intel SGX . In Proceedings of the 2017 USENIX Conference on Usenix Annual Technical Conference (USENIX ATC '17). USENIX Association , Berkeley, CA, USA, 285--298. http:\/\/dl.acm.org\/citation.cfm?id=3154690.3154718 Joshua Lind, Christian Priebe, Divya Muthukumaran, Dan O'Keeffe, Pierre-Louis Aublin, Florian Kelbert, Tobias Reiher, David Goltzsche, David Eyers, R\u00fcdiger Kapitza, Christof Fetzer, and Peter Pietzuch. 2017. Glamdring: Automatic Application Partitioning for Intel SGX. In Proceedings of the 2017 USENIX Conference on Usenix Annual Technical Conference (USENIX ATC '17). USENIX Association, Berkeley, CA, USA, 285--298. http:\/\/dl.acm.org\/citation.cfm?id=3154690.3154718"},{"key":"e_1_2_1_35_1","volume-title":"2018 USENIX Annual Technical Conference (USENIX ATC 18)","author":"Oleksenko Oleksii","year":"2018","unstructured":"Oleksii Oleksenko , Bohdan Trach , Robert Krahn , Mark Silberstein , and Christof Fetzer . 2018 . Varys: Protecting SGX Enclaves from Practical Side-Channel Attacks . In 2018 USENIX Annual Technical Conference (USENIX ATC 18) . USENIX Association, Boston, MA, 227--240. https:\/\/www.usenix.org\/conference\/atc18\/presentation\/oleksenko Oleksii Oleksenko, Bohdan Trach, Robert Krahn, Mark Silberstein, and Christof Fetzer. 2018. Varys: Protecting SGX Enclaves from Practical Side-Channel Attacks. In 2018 USENIX Annual Technical Conference (USENIX ATC 18). USENIX Association, Boston, MA, 227--240. https:\/\/www.usenix.org\/conference\/atc18\/presentation\/oleksenko"},{"key":"e_1_2_1_36_1","unstructured":"Ryan Puffer and Liza Poggemeyer. 2016. Guarded fabric and shielded VMs overview. https:\/\/docs.microsoft.com\/en-us\/windows-server\/virtualization\/guarded-fabric-shielded-vm\/guarded-fabric-and-shielded-vms .  Ryan Puffer and Liza Poggemeyer. 2016. Guarded fabric and shielded VMs overview. https:\/\/docs.microsoft.com\/en-us\/windows-server\/virtualization\/guarded-fabric-shielded-vm\/guarded-fabric-and-shielded-vms ."},{"key":"e_1_2_1_37_1","unstructured":"Riva Richmond. {n. d.}.  Riva Richmond. {n. d.}."},{"key":"e_1_2_1_38_1","volume-title":"Intel White Paper. Retrieved January","volume":"15","author":"Righini Marco","year":"2010","unstructured":"Marco Righini . 2010 . Enabling Intel virtualization technology features and benefits . Intel White Paper. Retrieved January , Vol. 15 (2010), 2012. Marco Righini. 2010. Enabling Intel virtualization technology features and benefits. Intel White Paper. Retrieved January , Vol. 15 (2010), 2012."},{"key":"e_1_2_1_39_1","unstructured":"Efraim Rotem and Senior Principal Engineer. 2015. Intel Architecture Code Name Skylake Deep Dive: A New Architecture to Manage Power Performance and Energy Efficiency. In Intel Developer Forum .  Efraim Rotem and Senior Principal Engineer. 2015. Intel Architecture Code Name Skylake Deep Dive: A New Architecture to Manage Power Performance and Energy Efficiency. In Intel Developer Forum ."},{"key":"e_1_2_1_40_1","unstructured":"Mark Russinovich. 2018. Azure confidential computing. https:\/\/azure.microsoft.com\/en-us\/blog\/azure-confidential-computing\/.  Mark Russinovich. 2018. Azure confidential computing. https:\/\/azure.microsoft.com\/en-us\/blog\/azure-confidential-computing\/."},{"key":"e_1_2_1_41_1","unstructured":"Samsung Electronics Co. Ltd. 2017. Samsung Knox Security Solution. https:\/\/www.samsungknox.com\/docs\/SamsungKnoxSecuritySolution.pdf .  Samsung Electronics Co. Ltd. 2017. Samsung Knox Security Solution. https:\/\/www.samsungknox.com\/docs\/SamsungKnoxSecuritySolution.pdf ."},{"key":"e_1_2_1_42_1","unstructured":"Evan R Sparks and Evan R Sparks. 2007. A security assessment of Trusted Platform Modules - computer science technical report TR2007--597 . (2007).  Evan R Sparks and Evan R Sparks. 2007. A security assessment of Trusted Platform Modules - computer science technical report TR2007--597 . (2007)."},{"key":"e_1_2_1_43_1","unstructured":"Gil Tene. 2018. WRK2 Http Benchmarking Took. https:\/\/github.com\/giltene\/wrk2 .  Gil Tene. 2018. WRK2 Http Benchmarking Took. https:\/\/github.com\/giltene\/wrk2 ."},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-45744-4_22"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3079856.3080208"},{"key":"e_1_2_1_46_1","unstructured":"Wired. 2009. Google Hack Attack Was Ultra Sophisticated . https:\/\/www.wired.com\/2010\/01\/operation-aurora\/.  Wired. 2009. Google Hack Attack Was Ultra Sophisticated . https:\/\/www.wired.com\/2010\/01\/operation-aurora\/."},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/2948618.2954330"}],"container-title":["Proceedings of the ACM on Measurement and Analysis of Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3322205.3311076","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3322205.3311076","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T00:25:54Z","timestamp":1750206354000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3322205.3311076"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,3,26]]},"references-count":46,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2019,3,26]]}},"alternative-id":["10.1145\/3322205.3311076"],"URL":"https:\/\/doi.org\/10.1145\/3322205.3311076","relation":{},"ISSN":["2476-1249"],"issn-type":[{"value":"2476-1249","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,3,26]]},"assertion":[{"value":"2019-03-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}