{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T02:49:30Z","timestamp":1783738170559,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":94,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,4,21]],"date-time":"2021-04-21T00:00:00Z","timestamp":1618963200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"NCSC\/GCHQ"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,4,21]]},"DOI":"10.1145\/3447786.3456255","type":"proceedings-article","created":{"date-parts":[[2021,4,22]],"date-time":"2021-04-22T06:18:11Z","timestamp":1619072291000},"page":"490-506","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":24,"title":["rkt-io"],"prefix":"10.1145","author":[{"given":"J\u00f6rg","family":"Thalheim","sequence":"first","affiliation":[{"name":"Technical University of Munich, Germany and The University of Edinburgh, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Harshavardhan","family":"Unnibhavi","sequence":"additional","affiliation":[{"name":"Technical University of Munich, Germany and The University of Edinburgh, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christian","family":"Priebe","sequence":"additional","affiliation":[{"name":"Imperial College London, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pramod","family":"Bhatotia","sequence":"additional","affiliation":[{"name":"Technical University of Munich, Germany and The University of Edinburgh, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Peter","family":"Pietzuch","sequence":"additional","affiliation":[{"name":"Imperial College London, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,4,21]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"https:\/\/nixos.org\/download.html. Last accessed","author":"Nix","year":"2021","unstructured":"Nix package manager. https:\/\/nixos.org\/download.html. Last accessed : March , 2021 . Nix package manager. https:\/\/nixos.org\/download.html. Last accessed: March, 2021."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23284"},{"key":"e_1_3_2_1_3_1","volume-title":"AMD Secure Encrypted Virtualization (SEV). https:\/\/developer.amd.com\/sev\/. Last accessed","author":"AMD.","year":"2021","unstructured":"AMD. AMD Secure Encrypted Virtualization (SEV). https:\/\/developer.amd.com\/sev\/. Last accessed : Mar , 2021 . AMD. AMD Secure Encrypted Virtualization (SEV). https:\/\/developer.amd.com\/sev\/. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_4_1","volume-title":"http:\/\/infocenter.arm.com\/help\/topic\/com.arm.doc.prd29-genc-009492c\/PRD29-GENC-009492C_trustzone_security_whitepaper.pdf. Last accessed","author":"ARM.","year":"2021","unstructured":"ARM. Building a secure system using trustzone technology. http:\/\/infocenter.arm.com\/help\/topic\/com.arm.doc.prd29-genc-009492c\/PRD29-GENC-009492C_trustzone_security_whitepaper.pdf. Last accessed : Mar , 2021 . ARM. Building a secure system using trustzone technology. http:\/\/infocenter.arm.com\/help\/topic\/com.arm.doc.prd29-genc-009492c\/PRD29-GENC-009492C_trustzone_security_whitepaper.pdf. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_5_1","volume-title":"Proceedings of the 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Arnautov S.","year":"2016","unstructured":"S. Arnautov , B. Trach , F. Gregor , T. Knauth , A. Martin , C. Priebe , J. Lind , D. Muthukumaran , D. O'Keeffe , M. L. Stillwell , D. Goltzsche , D. Eyers , R. Kapitza , P. Pietzuch , and C. Fetzer . SCONE: Secure Linux Containers with Intel SGX . In Proceedings of the 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI) , 2016 . S. Arnautov, B. Trach, F. Gregor, T. Knauth, A. Martin, C. Priebe, J. Lind, D. Muthukumaran, D. O'Keeffe, M. L. Stillwell, D. Goltzsche, D. Eyers, R. Kapitza, P. Pietzuch, and C. Fetzer. SCONE: Secure Linux Containers with Intel SGX. In Proceedings of the 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI), 2016."},{"key":"e_1_3_2_1_6_1","volume-title":"17th USENIX Conference on File and Storage Technologies (FAST)","author":"Bailleu M.","year":"2019","unstructured":"M. Bailleu , J. Thalheim , P. Bhatotia , C. Fetzer , M. Honda , and K. Vaswani . SPEICHER: Securing lsm-based key-value stores using shielded execution . In 17th USENIX Conference on File and Storage Technologies (FAST) , 2019 . M. Bailleu, J. Thalheim, P. Bhatotia, C. Fetzer, M. Honda, and K. Vaswani. SPEICHER: Securing lsm-based key-value stores using shielded execution. In 17th USENIX Conference on File and Storage Technologies (FAST), 2019."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.5555\/2685048.2685070"},{"key":"e_1_3_2_1_8_1","volume-title":"11th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Belay A.","year":"2014","unstructured":"A. Belay , G. Prekas , A. Klimovic , S. Grossman , C. Kozyrakis , and E. Bugnion . IX: A protected dataplane operating system for high throughput and low latency . In 11th USENIX Symposium on Operating Systems Design and Implementation (OSDI) , 2014 . A. Belay, G. Prekas, A. Klimovic, S. Grossman, C. Kozyrakis, and E. Bugnion. IX: A protected dataplane operating system for high throughput and low latency. In 11th USENIX Symposium on Operating Systems Design and Implementation (OSDI), 2014."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/224056.224077"},{"key":"e_1_3_2_1_10_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Biondo A.","year":"2018","unstructured":"A. Biondo , M. Conti , L. Davi , T. Frassetto , and A.-R. Sadeghi . The guard's dilemma : Efficient code-reuse attacks against intel SGX . In 27th USENIX Security Symposium (USENIX Security 18) , 2018 . A. Biondo, M. Conti, L. Davi, T. Frassetto, and A.-R. Sadeghi. The guard's dilemma: Efficient code-reuse attacks against intel SGX. In 27th USENIX Security Symposium (USENIX Security 18), 2018."},{"key":"e_1_3_2_1_11_1","volume-title":"Blobstore Filesystem. Last accessed","year":"2021","unstructured":"BlobFS : Blobstore Filesystem. Last accessed : Mar , 2021 . BlobFS: Blobstore Filesystem. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_12_1","volume-title":"11th USENIX Workshop on Offensive Technologies (WOOT 17)","author":"Brasser F.","year":"2017","unstructured":"F. Brasser , U. M\u00fcller , A. Dmitrienko , K. Kostiainen , S. Capkun , and A.-R. Sadeghi . Software grand exposure: SGX cache attacks are practical . In 11th USENIX Workshop on Offensive Technologies (WOOT 17) , 2017 . F. Brasser, U. M\u00fcller, A. Dmitrienko, K. Kostiainen, S. Capkun, and A.-R. Sadeghi. Software grand exposure: SGX cache attacks are practical. In 11th USENIX Workshop on Offensive Technologies (WOOT 17), 2017."},{"key":"e_1_3_2_1_13_1","volume-title":"Last accessed","author":"Bufferbloat","year":"2021","unstructured":"Bufferbloat project. Last accessed : Mar , 2021 . Bufferbloat project. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813700"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2451116.2451145"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/504390.504414"},{"key":"e_1_3_2_1_17_1","volume-title":"https:\/\/www.alibabacloud.com\/blog\/alibaba-clouds-next-generation-security-makes-gartners-report_595367. Last accessed","author":"Cloud A.","year":"2021","unstructured":"A. Cloud . Alibaba Cloud's Next-Generation Security Makes Gartner's Report . https:\/\/www.alibabacloud.com\/blog\/alibaba-clouds-next-generation-security-makes-gartners-report_595367. Last accessed : Mar , 2021 . A. Cloud. Alibaba Cloud's Next-Generation Security Makes Gartner's Report. https:\/\/www.alibabacloud.com\/blog\/alibaba-clouds-next-generation-security-makes-gartners-report_595367. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1807128.1807152"},{"key":"e_1_3_2_1_19_1","volume-title":"https:\/\/lwn.net\/Articles\/552904\/","author":"Corbet J.","year":"2013","unstructured":"J. Corbet . The multiqueue block layer. https:\/\/lwn.net\/Articles\/552904\/ , 2013 . Last accessed: Mar, 2021. J. Corbet. The multiqueue block layer. https:\/\/lwn.net\/Articles\/552904\/, 2013. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_20_1","volume-title":"Intel SGX Explained","author":"Costan V.","year":"2016","unstructured":"V. Costan and S. Devadas . Intel SGX Explained , 2016 . V. Costan and S. Devadas. Intel SGX Explained, 2016."},{"key":"e_1_3_2_1_21_1","volume-title":"Proceedings of the DPDK Userspace","author":"Darawsheh R.","year":"2018","unstructured":"R. Darawsheh . mbuf external buffer and usage examples . In Proceedings of the DPDK Userspace , Dublin , 2018 . R. Darawsheh. mbuf external buffer and usage examples. In Proceedings of the DPDK Userspace, Dublin, 2018."},{"key":"e_1_3_2_1_22_1","volume-title":"Last accessed","year":"2021","unstructured":"dm-crypt\/device encryption. Last accessed : Mar , 2021 . dm-crypt\/device encryption. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_23_1","volume-title":"WireGuard: Next Generation Kernel Network Tunnel. https:\/\/www.wireguard.com\/papers\/wireguard.pdf. Last accessed","author":"Donenfeld J. A.","year":"2021","unstructured":"J. A. Donenfeld . WireGuard: Next Generation Kernel Network Tunnel. https:\/\/www.wireguard.com\/papers\/wireguard.pdf. Last accessed : Mar , 2021 . J. A. Donenfeld. WireGuard: Next Generation Kernel Network Tunnel. https:\/\/www.wireguard.com\/papers\/wireguard.pdf. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_24_1","volume-title":"Last accessed","author":"Data","year":"2021","unstructured":"Data plane development kit (DPDK). Last accessed : Mar , 2021 . Data plane development kit (DPDK). Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_25_1","volume-title":"Present, Future. In netdev 2.1 Montreal","author":"Dumazet E.","year":"2017","unstructured":"E. Dumazet . Busy Polling: Past , Present, Future. In netdev 2.1 Montreal , 2017 . E. Dumazet. Busy Polling: Past, Present, Future. In netdev 2.1 Montreal, 2017."},{"key":"e_1_3_2_1_26_1","volume-title":"Proceedings of the Fifteenth ACM Symposium on Operating Systems Principles (SOSP)","author":"Engler D. R.","year":"1995","unstructured":"D. R. Engler , M. F. Kaashoek , and J. O'Toole . Exokernel : An operating system architecture for application-level resource management . In Proceedings of the Fifteenth ACM Symposium on Operating Systems Principles (SOSP) , 1995 . D. R. Engler, M. F. Kaashoek, and J. O'Toole. Exokernel: An operating system architecture for application-level resource management. In Proceedings of the Fifteenth ACM Symposium on Operating Systems Principles (SOSP), 1995."},{"key":"e_1_3_2_1_27_1","volume-title":"https:\/\/cloud.google.com\/blog\/products\/identity-security\/introducing-google-cloud-confidential-computing-with-confidential-vms. Last accessed","author":"Cloud Confidential Introducing Google","year":"2021","unstructured":"Introducing Google Cloud Confidential Computing with Confidential V Ms . https:\/\/cloud.google.com\/blog\/products\/identity-security\/introducing-google-cloud-confidential-computing-with-confidential-vms. Last accessed : Mar , 2021 . Introducing Google Cloud Confidential Computing with Confidential VMs. https:\/\/cloud.google.com\/blog\/products\/identity-security\/introducing-google-cloud-confidential-computing-with-confidential-vms. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3065913.3065915"},{"key":"e_1_3_2_1_29_1","volume-title":"Proceedings of the USENIX Annual Technical Conference (ATC)","author":"H\u00e4hnel M.","year":"2017","unstructured":"M. H\u00e4hnel , W. Cui , and M. Peinado . High-resolution side channels for untrusted operating systems . In Proceedings of the USENIX Annual Technical Conference (ATC) , 2017 . M. H\u00e4hnel, W. Cui, and M. Peinado. High-resolution side channels for untrusted operating systems. In Proceedings of the USENIX Annual Technical Conference (ATC), 2017."},{"key":"e_1_3_2_1_30_1","volume-title":"29th USENIX Security Symposium (USENIX Security)","author":"Herwig S.","year":"2020","unstructured":"S. Herwig , C. Garman , and D. Levin . Achieving keyless cdns with conclaves . In 29th USENIX Security Symposium (USENIX Security) , 2020 . S. Herwig, C. Garman, and D. Levin. Achieving keyless cdns with conclaves. In 29th USENIX Security Symposium (USENIX Security), 2020."},{"key":"e_1_3_2_1_31_1","volume-title":"15th USENIX Symposium on Networked Systems Design and Implementation (NSDI)","author":"Honda M.","year":"2018","unstructured":"M. Honda , G. Lettieri , L. Eggert , and D. Santry . PASTE: A network programming interface for non-volatile main memory . In 15th USENIX Symposium on Networked Systems Design and Implementation (NSDI) , 2018 . M. Honda, G. Lettieri, L. Eggert, and D. Santry. PASTE: A network programming interface for non-volatile main memory. In 15th USENIX Symposium on Networked Systems Design and Implementation (NSDI), 2018."},{"key":"e_1_3_2_1_32_1","volume-title":"https:\/\/discuss.httparchive.org\/t\/tracking-page-weight-over-time\/1049. Last accessed","author":"Tracking","year":"2021","unstructured":"Tracking page weight over time. https:\/\/discuss.httparchive.org\/t\/tracking-page-weight-over-time\/1049. Last accessed : Mar , 2021 . Tracking page weight over time. https:\/\/discuss.httparchive.org\/t\/tracking-page-weight-over-time\/1049. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_33_1","volume-title":"17th USENIX Symposium on Networked Systems Design and Implementation (NSDI)","author":"Hwang J.","year":"2020","unstructured":"J. Hwang , Q. Cai , A. Tang , and R. Agarwal . TCP = RDMA: Cpu-efficient remote storage access with i10 . In 17th USENIX Symposium on Networked Systems Design and Implementation (NSDI) , 2020 . J. Hwang, Q. Cai, A. Tang, and R. Agarwal. TCP = RDMA: Cpu-efficient remote storage access with i10. In 17th USENIX Symposium on Networked Systems Design and Implementation (NSDI), 2020."},{"key":"e_1_3_2_1_34_1","volume-title":"https:\/\/ark.intel.com\/content\/www\/us\/en\/ark\/products\/series\/96947\/intel-ssd-dc-p4600-series.html. Last accessed","author":"Series Product","year":"2021","unstructured":"Product page of Intel SSD DC P4600 Series . https:\/\/ark.intel.com\/content\/www\/us\/en\/ark\/products\/series\/96947\/intel-ssd-dc-p4600-series.html. Last accessed : Mar , 2021 . Product page of Intel SSD DC P4600 Series. https:\/\/ark.intel.com\/content\/www\/us\/en\/ark\/products\/series\/96947\/intel-ssd-dc-p4600-series.html. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_35_1","volume-title":"https:\/\/software.intel.com\/en-us\/sgx. Last accessed","author":"Guard Intel Software","year":"2021","unstructured":"Intel Software Guard Extensions (Intel SGX). https:\/\/software.intel.com\/en-us\/sgx. Last accessed : Mar , 2021 . Intel Software Guard Extensions (Intel SGX). https:\/\/software.intel.com\/en-us\/sgx. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_36_1","volume-title":"Last accessed","author":"Intel SGX","year":"2021","unstructured":"Intel SGX SDK. Last accessed : Mar , 2021 . Intel SGX SDK. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_37_1","volume-title":"http:\/\/www.spdk.io. Last accessed","author":"Performance Development Kit Intel Storage","year":"2021","unstructured":"Intel Storage Performance Development Kit . http:\/\/www.spdk.io. Last accessed : Mar , 2021 . Intel Storage Performance Development Kit. http:\/\/www.spdk.io. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_38_1","volume-title":"https:\/\/www.intel.com\/content\/www\/us\/en\/products\/docs\/network-io\/ethernet\/network-adapters\/ethernet-xl710-brief.html. Last accessed","author":"Product","year":"2021","unstructured":"Product page of XL710 network card family. https:\/\/www.intel.com\/content\/www\/us\/en\/products\/docs\/network-io\/ethernet\/network-adapters\/ethernet-xl710-brief.html. Last accessed : Mar , 2021 . Product page of XL710 network card family. https:\/\/www.intel.com\/content\/www\/us\/en\/products\/docs\/network-io\/ethernet\/network-adapters\/ethernet-xl710-brief.html. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_39_1","volume-title":"https:\/\/iperf.fr\/. Last accessed","author":"Perf - The ultimate speed test tool for TCP, UDP","year":"2021","unstructured":"i Perf - The ultimate speed test tool for TCP, UDP and SCTP. https:\/\/iperf.fr\/. Last accessed : Mar , 2021 . iPerf - The ultimate speed test tool for TCP, UDP and SCTP. https:\/\/iperf.fr\/. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_40_1","volume-title":"https:\/\/github.com\/axboe\/fio. Last accessed","author":"Axboe Jens","year":"2020","unstructured":"Jens Axboe . Flexible I\/O Tester . https:\/\/github.com\/axboe\/fio. Last accessed : Dec , 2020 . Jens Axboe. Flexible I\/O Tester. https:\/\/github.com\/axboe\/fio. Last accessed: Dec, 2020."},{"key":"e_1_3_2_1_41_1","volume-title":"Proceedings of the 11th USENIX Conference on Networked Systems Design and Implementationi (NSDI)","author":"Jeong E. Y.","year":"2014","unstructured":"E. Y. Jeong , S. Woo , M. Jamshed , H. Jeong , S. Ihm , D. Han , and K. Park . MTCP: A Highly Scalable User-Level TCP Stack for Multicore Systems . In Proceedings of the 11th USENIX Conference on Networked Systems Design and Implementationi (NSDI) , 2014 . E. Y. Jeong, S. Woo, M. Jamshed, H. Jeong, S. Ihm, D. Han, and K. Park. MTCP: A Highly Scalable User-Level TCP Stack for Multicore Systems. In Proceedings of the 11th USENIX Conference on Networked Systems Design and Implementationi (NSDI), 2014."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/2749469.2750392"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3302424.3303985"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3037697.3037732"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3190508.3190518"},{"key":"e_1_3_2_1_46_1","volume-title":"CoRR","author":"Kunkel R.","year":"2019","unstructured":"R. Kunkel , D. L. Quoc , F. Gregor , S. Arnautov , P. Bhatotia , and C. Fetzer . Tensorscone: A secure tensorflow framework using intel SGX . CoRR , 2019 . R. Kunkel, D. L. Quoc, F. Gregor, S. Arnautov, P. Bhatotia, and C. Fetzer. Tensorscone: A secure tensorflow framework using intel SGX. CoRR, 2019."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3064176.3064192"},{"key":"e_1_3_2_1_48_1","volume-title":"ChaCha20 and Poly1305 for IETF Protocols. https:\/\/tools.ietf.org\/html\/rfc7539. Last accessed","author":"Langley A.","year":"2021","unstructured":"A. Langley . rfc7539 : ChaCha20 and Poly1305 for IETF Protocols. https:\/\/tools.ietf.org\/html\/rfc7539. Last accessed : Mar , 2021 . A. Langley. rfc7539: ChaCha20 and Poly1305 for IETF Protocols. https:\/\/tools.ietf.org\/html\/rfc7539. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3342195.3387532"},{"key":"e_1_3_2_1_50_1","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Lee J.","year":"2017","unstructured":"J. Lee , J. Jang , Y. Jang , N. Kwak , Y. Choi , C. Choi , T. Kim , M. Peinado , and B. B. Kang . Hacking in darkness: Return-oriented programming against secure enclaves . In 26th USENIX Security Symposium (USENIX Security 17) , 2017 . J. Lee, J. Jang, Y. Jang, N. Kwak, Y. Choi, C. Choi, T. Kim, M. Peinado, and B. B. Kang. Hacking in darkness: Return-oriented programming against secure enclaves. In 26th USENIX Security Symposium (USENIX Security 17), 2017."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3341301.3359627"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/2619239.2626311"},{"key":"e_1_3_2_1_53_1","volume-title":"Proceedings of the Conference of the ACM Special Interest Group on Data Communication (SIGCOMM)","author":"Marinos I.","year":"2017","unstructured":"I. Marinos , R. N. Watson , M. Handley , and R. R. Stewart . Disk|crypt|net: Rethinking the stack for high-performance video streaming . In Proceedings of the Conference of the ACM Special Interest Group on Data Communication (SIGCOMM) , 2017 . I. Marinos, R. N. Watson, M. Handley, and R. R. Stewart. Disk|crypt|net: Rethinking the stack for high-performance video streaming. In Proceedings of the Conference of the ACM Special Interest Group on Data Communication (SIGCOMM), 2017."},{"key":"e_1_3_2_1_54_1","volume-title":"Azure confidential computing. https:\/\/azure.microsoft.com\/en-us\/solutions\/confidential-compute\/. Last accessed","author":"Azure Microsoft","year":"2021","unstructured":"Microsoft Azure . Azure confidential computing. https:\/\/azure.microsoft.com\/en-us\/solutions\/confidential-compute\/. Last accessed : Mar , 2021 . Microsoft Azure. Azure confidential computing. https:\/\/azure.microsoft.com\/en-us\/solutions\/confidential-compute\/. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_55_1","volume-title":"an implementation of the C standard library. https:\/\/musl.libc.org\/. Last accessed","year":"2021","unstructured":"musl : an implementation of the C standard library. https:\/\/musl.libc.org\/. Last accessed : Mar , 2021 . musl: an implementation of the C standard library. https:\/\/musl.libc.org\/. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_56_1","volume-title":"https:\/\/www.mysql.com\/. Last accessed","author":"SQL.","year":"2021","unstructured":"My SQL. https:\/\/www.mysql.com\/. Last accessed : Mar , 2021 . MySQL. https:\/\/www.mysql.com\/. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_57_1","volume-title":"14th USENIX Symposium on Networked Systems Design and Implementation (NSDI)","author":"Nanavati M.","year":"2017","unstructured":"M. Nanavati , J. Wires , and A. Warfield . Decibel: Isolation and sharing in disaggregated rack-scale storage . In 14th USENIX Symposium on Networked Systems Design and Implementation (NSDI) , 2017 . M. Nanavati, J. Wires, and A. Warfield. Decibel: Isolation and sharing in disaggregated rack-scale storage. In 14th USENIX Symposium on Networked Systems Design and Implementation (NSDI), 2017."},{"key":"e_1_3_2_1_58_1","volume-title":"https:\/\/www.nginx.com\/. Last accessed","author":"Server Nginx Web","year":"2021","unstructured":"Nginx Web Server . https:\/\/www.nginx.com\/. Last accessed : Mar , 2021 . Nginx Web Server. https:\/\/www.nginx.com\/. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_59_1","volume-title":"9th RoEduNet IEEE International Conference","author":"Purdila O.","year":"2010","unstructured":"O. Purdila and L. A. Grijincu and N. Tapus . Lkl: The linux kernel library . In 9th RoEduNet IEEE International Conference , 2010 . O. Purdila and L. A. Grijincu and N. Tapus. Lkl: The linux kernel library. In 9th RoEduNet IEEE International Conference, 2010."},{"key":"e_1_3_2_1_60_1","volume-title":"Last accessed","author":"Flame Graphs CPU","year":"2021","unstructured":"Off- CPU Flame Graphs . Last accessed : Mar , 2021 . Off-CPU Flame Graphs. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/3219617.3219662"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/3064176.3064219"},{"key":"e_1_3_2_1_63_1","volume-title":"11th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Peter S.","year":"2014","unstructured":"S. Peter , J. Li , I. Zhang , D. R. K. Ports , D. Woos , A. Krishnamurthy , T. Anderson , and T. Roscoe . Arrakis: The operating system is the control plane . In 11th USENIX Symposium on Operating Systems Design and Implementation (OSDI) , 2014 . S. Peter, J. Li, I. Zhang, D. R. K. Ports, D. Woos, A. Krishnamurthy, T. Anderson, and T. Roscoe. Arrakis: The operating system is the control plane. In 11th USENIX Symposium on Operating Systems Design and Implementation (OSDI), 2014."},{"key":"e_1_3_2_1_64_1","volume-title":"15th USENIX Symposium on Networked Systems Design and Implementation (NSDI)","author":"Poddar R.","year":"2018","unstructured":"R. Poddar , C. Lan , R. A. Popa , and S. Ratnasamy . Safebricks: Shielding network functions in the cloud . In 15th USENIX Symposium on Networked Systems Design and Implementation (NSDI) , 2018 . R. Poddar, C. Lan, R. A. Popa, and S. Ratnasamy. Safebricks: Shielding network functions in the cloud. In 15th USENIX Symposium on Networked Systems Design and Implementation (NSDI), 2018."},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/1950365.1950399"},{"key":"e_1_3_2_1_66_1","volume-title":"Sgx-lkl: Securing the host os interface for trusted execution","author":"Priebe C.","year":"2019","unstructured":"C. Priebe , D. Muthukumaran , J. Lind , H. Zhu , S. Cui , V. A. Sartakov , and P. Pietzuch . Sgx-lkl: Securing the host os interface for trusted execution , 2019 . C. Priebe, D. Muthukumaran, J. Lind, H. Zhu, S. Cui, V. A. Sartakov, and P. Pietzuch. Sgx-lkl: Securing the host os interface for trusted execution, 2019."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00025"},{"key":"e_1_3_2_1_68_1","volume-title":"https:\/\/redis.io\/. Last accessed","year":"2021","unstructured":"Redis. https:\/\/redis.io\/. Last accessed : Mar , 2021 . Redis. https:\/\/redis.io\/. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_69_1","volume-title":"Keystone Open-source Secure Hardware Enclave. https:\/\/keystone-enclave.org\/. Last accessed","author":"V.","year":"2021","unstructured":"RISC- V. Keystone Open-source Secure Hardware Enclave. https:\/\/keystone-enclave.org\/. Last accessed : Mar , 2021 . RISC-V. Keystone Open-source Secure Hardware Enclave. https:\/\/keystone-enclave.org\/. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_70_1","volume-title":"Communications of the ACM","author":"Rizzo L.","year":"2012","unstructured":"L. Rizzo . Revisiting network I\/O AP Is : The Netmap Framework . Communications of the ACM , 2012 . L. Rizzo. Revisiting network I\/O APIs: The Netmap Framework. Communications of the ACM, 2012."},{"key":"e_1_3_2_1_71_1","volume-title":"Proceedings of the 1st USENIX Workshop on Hot Topics in Cloud Computing (HotCloud)","author":"Santos N.","year":"2009","unstructured":"N. Santos , K. P. Gummadi , and R. Rodrigues . Towards Trusted Cloud Computing . In Proceedings of the 1st USENIX Workshop on Hot Topics in Cloud Computing (HotCloud) , 2009 . N. Santos, K. P. Gummadi, and R. Rodrigues. Towards Trusted Cloud Computing. In Proceedings of the 1st USENIX Workshop on Hot Topics in Cloud Computing (HotCloud), 2009."},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.5555\/2442626.2442653"},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.10"},{"key":"e_1_3_2_1_74_1","volume-title":"https:\/\/sconedocs.github.io\/SCONE_Fileshield\/. Last accessed","author":"Scone","year":"2021","unstructured":"Scone file protection. https:\/\/sconedocs.github.io\/SCONE_Fileshield\/. Last accessed : Mar , 2021 . Scone file protection. https:\/\/sconedocs.github.io\/SCONE_Fileshield\/. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23500"},{"key":"e_1_3_2_1_76_1","volume-title":"Proceedings of the 9th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Soares L.","year":"2010","unstructured":"L. Soares and M. Stumm . FlexSC: Flexible System Call Scheduling with Exception-less System Calls . In Proceedings of the 9th USENIX Symposium on Operating Systems Design and Implementation (OSDI) , 2010 . L. Soares and M. Stumm. FlexSC: Flexible System Call Scheduling with Exception-less System Calls. In Proceedings of the 9th USENIX Symposium on Operating Systems Design and Implementation (OSDI), 2010."},{"key":"e_1_3_2_1_77_1","volume-title":"https:\/\/www.sqlite.org\/speed.html. Last accessed","year":"2021","unstructured":"speedtest. https:\/\/www.sqlite.org\/speed.html. Last accessed : Mar , 2021 . speedtest. https:\/\/www.sqlite.org\/speed.html. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_78_1","volume-title":"https:\/\/www.sqlite.org\/. Last accessed","year":"2021","unstructured":"SQLite. https:\/\/www.sqlite.org\/. Last accessed : Mar , 2021 . SQLite. https:\/\/www.sqlite.org\/. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_79_1","volume-title":"Last accessed","author":"Hardware Supported","year":"2021","unstructured":"Supported Hardware . Last accessed : Feb , 2021 . Supported Hardware. Last accessed: Feb, 2021."},{"key":"e_1_3_2_1_80_1","volume-title":"https:\/\/github.com\/akopytov\/sysbench. Last accessed","year":"2021","unstructured":"sysbench. https:\/\/github.com\/akopytov\/sysbench. Last accessed : Mar , 2021 . sysbench. https:\/\/github.com\/akopytov\/sysbench. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_81_1","volume-title":"Proceedings of the 7th Symposium on Operating Systems Design and Implementation (OSDI)","author":"Ta-Min R.","year":"2006","unstructured":"R. Ta-Min , L. Litty , and D. Lie . Splitting interfaces: Making trust between applications and operating systems configurable . In Proceedings of the 7th Symposium on Operating Systems Design and Implementation (OSDI) , 2006 . R. Ta-Min, L. Litty, and D. Lie. Splitting interfaces: Making trust between applications and operating systems configurable. In Proceedings of the 7th Symposium on Operating Systems Design and Implementation (OSDI), 2006."},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1145\/3419111.3421273"},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1145\/3185467.3185469"},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319647.3325835"},{"key":"e_1_3_2_1_85_1","volume-title":"Proceedings of the USENIX Annual Technical Conference (USENIX ATC)","author":"Tsai C.-C.","year":"2017","unstructured":"C.-C. Tsai , D. E. Porter , and M. Vij . Graphene-SGX: A practical library OS for unmodified applications on SGX . In Proceedings of the USENIX Annual Technical Conference (USENIX ATC) , 2017 . C.-C. Tsai, D. E. Porter, and M. Vij. Graphene-SGX: A practical library OS for unmodified applications on SGX. In Proceedings of the USENIX Annual Technical Conference (USENIX ATC), 2017."},{"key":"e_1_3_2_1_86_1","volume-title":"Proceedings of the 27th USENIX Security Symposium (USENIX Security)","author":"Bulck J. Van","year":"2018","unstructured":"J. Van Bulck , M. Minkin , O. Weisse , D. Genkin , B. Kasikci , F. Piessens , M. Silberstein , T. F. Wenisch , Y. Yarom , and R. Strackx . Foreshadow: Extracting the keys to the Intel SGX kingdom with transient out-of-order execution . In Proceedings of the 27th USENIX Security Symposium (USENIX Security) , 2018 . J. Van Bulck, M. Minkin, O. Weisse, D. Genkin, B. Kasikci, F. Piessens, M. Silberstein, T. F. Wenisch, Y. Yarom, and R. Strackx. Foreshadow: Extracting the keys to the Intel SGX kingdom with transient out-of-order execution. In Proceedings of the 27th USENIX Security Symposium (USENIX Security), 2018."},{"key":"e_1_3_2_1_87_1","volume-title":"https:\/\/blog.cloudflare.com\/how-expensive-is-crypto-anyway","author":"Krasnov Vlad","year":"2017","unstructured":"Vlad Krasnov . How \"expensive\" is crypto anyway. https:\/\/blog.cloudflare.com\/how-expensive-is-crypto-anyway , 2017 . Last accessed: Mar, 2021. Vlad Krasnov. How \"expensive\" is crypto anyway. https:\/\/blog.cloudflare.com\/how-expensive-is-crypto-anyway, 2017. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_88_1","volume-title":"Computer Security - ESORICS","author":"Kurmus Nico","year":"2016","unstructured":"Weichbrodt, Nico and Kurmus , Anil and Pietzuch , Peter and Kapitza , R\u00fcdiger. AsyncShock : Exploiting Synchronisation Bugs in Intel SGX Enclaves . In Computer Security - ESORICS , 2016 . Weichbrodt, Nico and Kurmus, Anil and Pietzuch, Peter and Kapitza, R\u00fcdiger. AsyncShock: Exploiting Synchronisation Bugs in Intel SGX Enclaves. In Computer Security - ESORICS, 2016."},{"key":"e_1_3_2_1_89_1","volume-title":"https:\/\/github.com\/wg\/wrk. Last accessed","year":"2021","unstructured":"wrk. https:\/\/github.com\/wg\/wrk. Last accessed : Mar , 2021 . wrk. https:\/\/github.com\/wg\/wrk. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_90_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.45"},{"key":"e_1_3_2_1_91_1","volume-title":"2016 USENIX Annual Technical Conference (USENIX ATC)","author":"Yasukata K.","year":"2016","unstructured":"K. Yasukata , M. Honda , D. Santry , and L. Eggert . Stackmap: Low-latency networking with the OS stack and dedicated nics . In 2016 USENIX Annual Technical Conference (USENIX ATC) , 2016 . K. Yasukata, M. Honda, D. Santry, and L. Eggert. Stackmap: Low-latency networking with the OS stack and dedicated nics. In 2016 USENIX Annual Technical Conference (USENIX ATC), 2016."},{"key":"e_1_3_2_1_92_1","volume-title":"Linux kernel: Introduction of hybrid polling in the blk-mq subsystem. https:\/\/lwn.net\/Articles\/735275","author":"Yates T.","year":"2017","unstructured":"T. Yates . Linux kernel: Introduction of hybrid polling in the blk-mq subsystem. https:\/\/lwn.net\/Articles\/735275 , 2017 . Last accessed: Mar, 2021. T. Yates. Linux kernel: Introduction of hybrid polling in the blk-mq subsystem. https:\/\/lwn.net\/Articles\/735275, 2017. Last accessed: Mar, 2021."},{"key":"e_1_3_2_1_93_1","doi-asserted-by":"publisher","DOI":"10.1145\/3317550.3321422"},{"key":"e_1_3_2_1_94_1","volume-title":"Proceedings of the 14th USENIX Symposium on Networked Systems Design and Implementation (NSDI)","author":"Zheng W.","year":"2017","unstructured":"W. Zheng , A. Dave , J. G. Beekman , R. A. Popa , J. E. Gonzalez , and I. Stoica . Opaque: An Oblivious and Encrypted Distributed Analytics Platform . In Proceedings of the 14th USENIX Symposium on Networked Systems Design and Implementation (NSDI) , 2017 . W. Zheng, A. Dave, J. G. Beekman, R. A. Popa, J. E. Gonzalez, and I. Stoica. Opaque: An Oblivious and Encrypted Distributed Analytics Platform. In Proceedings of the 14th USENIX Symposium on Networked Systems Design and Implementation (NSDI), 2017."}],"event":{"name":"EuroSys '21: Sixteenth European Conference on Computer Systems","location":"Online Event United Kingdom","acronym":"EuroSys '21","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the Sixteenth European Conference on Computer Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3447786.3456255","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3447786.3456255","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:48:04Z","timestamp":1750193284000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3447786.3456255"}},"subtitle":["a direct I\/O stack for shielded execution"],"short-title":[],"issued":{"date-parts":[[2021,4,21]]},"references-count":94,"alternative-id":["10.1145\/3447786.3456255","10.1145\/3447786"],"URL":"https:\/\/doi.org\/10.1145\/3447786.3456255","relation":{},"subject":[],"published":{"date-parts":[[2021,4,21]]},"assertion":[{"value":"2021-04-21","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}