{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,26]],"date-time":"2026-07-26T05:14:12Z","timestamp":1785042852652,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":58,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,3,9]],"date-time":"2020-03-09T00:00:00Z","timestamp":1583712000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Key R&D Program of China","award":["2017YFB0802901"],"award-info":[{"award-number":["2017YFB0802901"]}]},{"name":"National Natural Science Foundation of China","award":["61877035"],"award-info":[{"award-number":["61877035"]}]},{"name":"National Natural Science Foundation of China","award":["61772303"],"award-info":[{"award-number":["61772303"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,3,9]]},"DOI":"10.1145\/3373376.3378469","type":"proceedings-article","created":{"date-parts":[[2020,3,13]],"date-time":"2020-03-13T22:37:01Z","timestamp":1584139021000},"page":"955-970","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":139,"title":["Occlum"],"prefix":"10.1145","author":[{"given":"Youren","family":"Shen","sequence":"first","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hongliang","family":"Tian","sequence":"additional","affiliation":[{"name":"Ant Financial Services Group, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu","family":"Chen","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kang","family":"Chen","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Runji","family":"Wang","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yi","family":"Xu","sequence":"additional","affiliation":[{"name":"Purdue University, West Lafayette, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yubin","family":"Xia","sequence":"additional","affiliation":[{"name":"Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shoumeng","family":"Yan","sequence":"additional","affiliation":[{"name":"Ant Financial Services Group, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,3,13]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2018. Overview of Intel Protected File System Library Using Software Guard Extensions. https:\/\/software.intel.com\/en-us\/articles\/overviewof- intel-protected-file-system-library-using-software-guardextensions  2018. Overview of Intel Protected File System Library Using Software Guard Extensions. https:\/\/software.intel.com\/en-us\/articles\/overviewof- intel-protected-file-system-library-using-software-guardextensions"},{"key":"e_1_3_2_1_2_1","unstructured":"2019. byte-unixbench. https:\/\/github.com\/kdlucas\/byte-unixbench  2019. byte-unixbench. https:\/\/github.com\/kdlucas\/byte-unixbench"},{"key":"e_1_3_2_1_3_1","unstructured":"2019. Download the Windows version of PostgreSQL. https:\/\/ www.postgresql.org\/download\/windows\/  2019. Download the Windows version of PostgreSQL. https:\/\/ www.postgresql.org\/download\/windows\/"},{"key":"e_1_3_2_1_4_1","unstructured":"2019. fish shell. https:\/\/fishshell.com  2019. fish shell. https:\/\/fishshell.com"},{"key":"e_1_3_2_1_5_1","unstructured":"2019. Large single compilation-unit C programs. http:\/\/ people.csail.mit.edu\/smcc\/projects\/single-file-programs  2019. Large single compilation-unit C programs. http:\/\/ people.csail.mit.edu\/smcc\/projects\/single-file-programs"},{"key":"e_1_3_2_1_6_1","unstructured":"2019. Lighttpd fly light. https:\/\/www.lighttpd.net  2019. Lighttpd fly light. https:\/\/www.lighttpd.net"},{"key":"e_1_3_2_1_7_1","unstructured":"2019. The Linux FUSE (Filesystem in Userspace) interface. https:\/\/ github.com\/libfuse\/libfuse  2019. The Linux FUSE (Filesystem in Userspace) interface. https:\/\/ github.com\/libfuse\/libfuse"},{"key":"e_1_3_2_1_8_1","unstructured":"2019. The LLVM Compiler Infrastructure. http:\/\/llvm.org\/  2019. The LLVM Compiler Infrastructure. http:\/\/llvm.org\/"},{"key":"e_1_3_2_1_9_1","unstructured":"2019. musl libc. https:\/\/www.musl-libc.org\/  2019. musl libc. https:\/\/www.musl-libc.org\/"},{"key":"e_1_3_2_1_10_1","unstructured":"2019. Occlum: A memory-safe multi-process LibOS for Intel SGX. https: \/\/github.com\/anonymous8923\/occlum  2019. Occlum: A memory-safe multi-process LibOS for Intel SGX. https: \/\/github.com\/anonymous8923\/occlum"},{"key":"e_1_3_2_1_11_1","unstructured":"2019. Redis on Windows. https:\/\/github.com\/ServiceStack\/rediswindows  2019. Redis on Windows. https:\/\/github.com\/ServiceStack\/rediswindows"},{"key":"e_1_3_2_1_12_1","unstructured":"2019. The Rust Programming Language. https:\/\/www.rust-lang.org\/  2019. The Rust Programming Language. https:\/\/www.rust-lang.org\/"},{"key":"e_1_3_2_1_13_1","unstructured":"2019. Single Address Space OperatingSystem. http: \/\/wiki.c2.com\/?SingleAddressSpaceOperatingSystem  2019. Single Address Space OperatingSystem. http: \/\/wiki.c2.com\/?SingleAddressSpaceOperatingSystem"},{"key":"e_1_3_2_1_14_1","unstructured":"2019. sshd - OpenSSH SSH daemon. https:\/\/linux.die.net\/man\/8\/sshd  2019. sshd - OpenSSH SSH daemon. https:\/\/linux.die.net\/man\/8\/sshd"},{"key":"e_1_3_2_1_15_1","unstructured":"2019. Using Apache With Microsoft Windows. http:\/\/structure.usc.edu\/ apache\/windows.html  2019. Using Apache With Microsoft Windows. http:\/\/structure.usc.edu\/ apache\/windows.html"},{"key":"e_1_3_2_1_16_1","unstructured":"2019. Zydis: Fast and lightweight x86\/x86--64 disassembler library. https: \/\/zydis.re\/  2019. Zydis: Fast and lightweight x86\/x86--64 disassembler library. https: \/\/zydis.re\/"},{"key":"e_1_3_2_1_17_1","volume-title":"Ullman","author":"Aho Alfred V.","year":"2006"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241140"},{"key":"e_1_3_2_1_19_1","volume-title":"SCONE: Secure Linux Containers with Intel SGX. In 12th USENIX Symposium on Operating Systems Design and Implementation, OSDI","author":"Arnautov Sergei","year":"2016"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3317550.3321435"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/2799647"},{"key":"e_1_3_2_1_22_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Bulck Jo Van","year":"2018"},{"key":"e_1_3_2_1_23_1","volume-title":"Control-Flow Bending: On the Effectiveness of Control-Flow Integrity. In 24th USENIX Security Symposium (USENIX Security 15)","author":"Carlini Nicholas"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/2499368.2451145"},{"key":"e_1_3_2_1_25_1","volume-title":"Lai","author":"Chen Guoxing","year":"2018"},{"key":"e_1_3_2_1_26_1","unstructured":"Jonathan Corbet. 2015. Memory protection keys. https:\/\/lwn.net\/ Articles\/643797\/  Jonathan Corbet. 2015. Memory protection keys. https:\/\/lwn.net\/ Articles\/643797\/"},{"key":"e_1_3_2_1_27_1","volume-title":"CINT2006 (Integer Component of SPEC CPU2006)","author":"Standard Performance Evaluation Corporation","year":"2019"},{"key":"e_1_3_2_1_28_1","unstructured":"Casper Dik. 2018. posix_spawn() as an actual system call. https: \/\/blogs.oracle.com\/solaris\/posixspawn-as-an-actual-system-call  Casper Dik. 2018. posix_spawn() as an actual system call. https: \/\/blogs.oracle.com\/solaris\/posixspawn-as-an-actual-system-call"},{"key":"e_1_3_2_1_29_1","volume-title":"Shielding Software From Privileged Side- Channel Attacks. In 27th USENIX Security Symposium (USENIX Security 18)","author":"Dong Xiaowan","year":"2018"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/224056.224076"},{"key":"e_1_3_2_1_31_1","unstructured":"Fluentd Project. 2019. Fluentd is an open source data collector for unified logging layer. https:\/\/www.fluentd.org\/  Fluentd Project. 2019. Fluentd is an open source data collector for unified logging layer. https:\/\/www.fluentd.org\/"},{"key":"e_1_3_2_1_32_1","unstructured":"The Apache Software Foundation. 2019. ab - Apache HTTP server benchmarking tool. https:\/\/httpd.apache.org\/docs\/2.4\/programs\/ab.html  The Apache Software Foundation. 2019. ab - Apache HTTP server benchmarking tool. https:\/\/httpd.apache.org\/docs\/2.4\/programs\/ab.html"},{"key":"e_1_3_2_1_33_1","unstructured":"Inc Free Software Foundation. 2019. GCC the GNU Compiler Collection. https:\/\/www.gnu.org\/software\/gcc  Inc Free Software Foundation. 2019. GCC the GNU Compiler Collection. https:\/\/www.gnu.org\/software\/gcc"},{"key":"e_1_3_2_1_34_1","unstructured":"GNU. 2019. Auxiliary Vector. https:\/\/www.gnu.org\/software\/libc\/ manual\/htmlnode\/Auxiliary-Vector.html  GNU. 2019. Auxiliary Vector. https:\/\/www.gnu.org\/software\/libc\/ manual\/htmlnode\/Auxiliary-Vector.html"},{"key":"e_1_3_2_1_35_1","volume-title":"Out of Control: Overcoming Control-Flow Integrity. In 2014 IEEE Symposium on Security and Privacy. 575--589","author":"G\u00f6ktas E.","year":"2014"},{"key":"e_1_3_2_1_36_1","volume-title":"Ryoan: A Distributed Sandbox for Untrusted Computation on Secret Data. In 12th USENIX Symposium on Operating Systems Design and Implementation, OSDI 2016","author":"Hunt Tyler","year":"2016"},{"key":"e_1_3_2_1_37_1","unstructured":"Intel. 2013. Introduction to Intel(R) Memory Protection Extensions. https:\/\/software.intel.com\/en-us\/articles\/introduction-to-intelmemory- protection-extensions  Intel. 2013. Introduction to Intel(R) Memory Protection Extensions. https:\/\/software.intel.com\/en-us\/articles\/introduction-to-intelmemory- protection-extensions"},{"key":"e_1_3_2_1_38_1","unstructured":"Intel. 2019. Intel SGX for Linux. https:\/\/github.com\/intel\/linux-sgx  Intel. 2019. Intel SGX for Linux. https:\/\/github.com\/intel\/linux-sgx"},{"key":"e_1_3_2_1_39_1","unstructured":"Intel. 2019. Intel(R) Software Guard Extensions SDK. https:\/\/ software.intel.com\/en-us\/sgx-sdk\/documentation  Intel. 2019. Intel(R) Software Guard Extensions SDK. https:\/\/ software.intel.com\/en-us\/sgx-sdk\/documentation"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3064176.3064217"},{"key":"e_1_3_2_1_41_1","volume-title":"Proceedings of the 13th USENIX Security Symposium, August 9--13","author":"Kr\u00fcgel Christopher","year":"2004"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3064176.3064192"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/2954680.2872372"},{"key":"e_1_3_2_1_45_1","volume-title":"2018 USENIX Annual Technical Conference, USENIX ATC 2018","author":"Oleksenko Oleksii","year":"2018"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/1961295.1950399"},{"key":"e_1_3_2_1_47_1","volume-title":"The Art of UNIX Programming. Pearson Education. [48] RedHat","author":"Raymond Eric S.","year":"2019"},{"key":"e_1_3_2_1_48_1","volume-title":"Disassembly of Executable Code Revisited. In 9th Working Conference on Reverse Engineering (WCRE 2002","author":"Schwarz Benjamin","year":"2002"},{"key":"e_1_3_2_1_49_1","volume-title":"19th USENIX Security Symposium","author":"Sehr David","year":"2010"},{"key":"e_1_3_2_1_50_1","volume-title":"T-SGX: Eradicating Controlled-Channel Attacks Against Enclave Programs. In 24th Annual Network and Distributed System Security Symposium, NDSS 2017","author":"Shih Ming-Wei","year":"2017"},{"key":"e_1_3_2_1_51_1","volume-title":"Panoply: Low-TCB Linux Applications With SGX Enclaves. In 24th Annual Network and Distributed System Security Symposium, NDSS 2017","author":"Shinde Shweta","year":"2017"},{"key":"e_1_3_2_1_52_1","volume-title":"Firmalice - Automatic Detection of Authentication Bypass Vulnerabilities in Binary Firmware. In 22nd Annual Network and Distributed System Security Symposium, NDSS 2015","author":"Shoshitaishvili Yan","year":"2015"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/2908080.2908113"},{"key":"e_1_3_2_1_54_1","volume-title":"USENIX ATC","author":"Porter Donald E.","year":"2017"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/168619.168635"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354241"},{"key":"e_1_3_2_1_57_1","volume-title":"Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security","author":"Wang Wenhao"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076739"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046713"}],"event":{"name":"ASPLOS '20: Architectural Support for Programming Languages and Operating Systems","location":"Lausanne Switzerland","acronym":"ASPLOS '20","sponsor":["SIGPLAN ACM Special Interest Group on Programming Languages","SIGOPS ACM Special Interest Group on Operating Systems","SIGARCH ACM Special Interest Group on Computer Architecture","SIGBED ACM Special Interest Group on Embedded Systems"]},"container-title":["Proceedings of the Twenty-Fifth International Conference on Architectural Support for Programming Languages and Operating Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3373376.3378469","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3373376.3378469","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:32:59Z","timestamp":1750199579000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3373376.3378469"}},"subtitle":["Secure and Efficient Multitasking Inside a Single Enclave of Intel SGX"],"short-title":[],"issued":{"date-parts":[[2020,3,9]]},"references-count":58,"alternative-id":["10.1145\/3373376.3378469","10.1145\/3373376"],"URL":"https:\/\/doi.org\/10.1145\/3373376.3378469","relation":{},"subject":[],"published":{"date-parts":[[2020,3,9]]},"assertion":[{"value":"2020-03-13","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}