{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T20:05:38Z","timestamp":1778789138114,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":85,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,10,26]],"date-time":"2021-10-26T00:00:00Z","timestamp":1635206400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Key Research & Development Program","award":["2020YFB2104104"],"award-info":[{"award-number":["2020YFB2104104"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62002218,61925206,61972244,U19A2060"],"award-info":[{"award-number":["62002218,61925206,61972244,U19A2060"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,10,26]]},"DOI":"10.1145\/3477132.3483554","type":"proceedings-article","created":{"date-parts":[[2021,10,19]],"date-time":"2021-10-19T15:59:18Z","timestamp":1634659158000},"page":"638-654","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":40,"title":["TwinVisor"],"prefix":"10.1145","author":[{"given":"Dingji","family":"Li","sequence":"first","affiliation":[{"name":"Institute of Parallel and Distributed Systems, Shanghai Jiao Tong University, MoE Key Lab of Artificial Intelligence, AI Institute, Shanghai Jiao Tong University and Engineering Research Center for Domain-specific Operating Systems, Ministry of Education, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zeyu","family":"Mi","sequence":"additional","affiliation":[{"name":"Institute of Parallel and Distributed Systems, Shanghai Jiao Tong University and Engineering Research Center for Domain-specific Operating Systems, Ministry of Education, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yubin","family":"Xia","sequence":"additional","affiliation":[{"name":"Institute of Parallel and Distributed Systems, Shanghai Jiao Tong University and Engineering Research Center for Domain-specific Operating Systems, Ministry of Education, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Binyu","family":"Zang","sequence":"additional","affiliation":[{"name":"Institute of Parallel and Distributed Systems, Shanghai Jiao Tong University and Engineering Research Center for Domain-specific Operating Systems, Ministry of Education, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haibo","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute of Parallel and Distributed Systems, Shanghai Jiao Tong University and Engineering Research Center for Domain-specific Operating Systems, Ministry of Education, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haibing","family":"Guan","sequence":"additional","affiliation":[{"name":"Shanghai Key Laboratory of Scalable Computing and Systems, Shanghai Jiao Tong University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,10,26]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"https:\/\/developer.amd.com\/sev\/. Referenced","author":"Amd","year":"2021","unstructured":"Amd secure encrypted virtualization (sev). https:\/\/developer.amd.com\/sev\/. Referenced September 2021 . Amd secure encrypted virtualization (sev). https:\/\/developer.amd.com\/sev\/. Referenced September 2021."},{"key":"e_1_3_2_1_2_1","volume-title":"Strengthening vm isolation with itegrity protection and more. https:\/\/www.amd.com\/system\/files\/TechDocs\/SEV-SNP-strengthening-vm-isolation-with-integrity-protection-and-more.pdf. Referenced","author":"Amd","year":"2021","unstructured":"Amd sev-snp : Strengthening vm isolation with itegrity protection and more. https:\/\/www.amd.com\/system\/files\/TechDocs\/SEV-SNP-strengthening-vm-isolation-with-integrity-protection-and-more.pdf. Referenced September 2021 . Amd sev-snp: Strengthening vm isolation with itegrity protection and more. https:\/\/www.amd.com\/system\/files\/TechDocs\/SEV-SNP-strengthening-vm-isolation-with-integrity-protection-and-more.pdf. Referenced September 2021."},{"key":"e_1_3_2_1_3_1","volume-title":"for armv8-a architecture profile. https:\/\/developer.arm.com\/architectures\/architecture-security-features\/threats-andcountermeasures#specbar. Referenced","author":"Arm","year":"2021","unstructured":"Arm architecture reference manual armv8 , for armv8-a architecture profile. https:\/\/developer.arm.com\/architectures\/architecture-security-features\/threats-andcountermeasures#specbar. Referenced September 2021 . Arm architecture reference manual armv8, for armv8-a architecture profile. https:\/\/developer.arm.com\/architectures\/architecture-security-features\/threats-andcountermeasures#specbar. Referenced September 2021."},{"key":"e_1_3_2_1_4_1","volume-title":"https:\/\/static.linaro.org\/connect\/armcca\/presentations\/CCATechEvent-210623-MC.pdf. Referenced","author":"Arm","year":"2021","unstructured":"Arm cca future enablement plans. https:\/\/static.linaro.org\/connect\/armcca\/presentations\/CCATechEvent-210623-MC.pdf. Referenced September 2021 . Arm cca future enablement plans. https:\/\/static.linaro.org\/connect\/armcca\/presentations\/CCATechEvent-210623-MC.pdf. Referenced September 2021."},{"key":"e_1_3_2_1_5_1","volume-title":"https:\/\/developer.arm.com\/documentation\/ddi0615\/latest\/. Referenced","author":"Arm","year":"2021","unstructured":"Arm cca hardware architecture. https:\/\/developer.arm.com\/documentation\/ddi0615\/latest\/. Referenced September 2021 . Arm cca hardware architecture. https:\/\/developer.arm.com\/documentation\/ddi0615\/latest\/. Referenced September 2021."},{"key":"e_1_3_2_1_6_1","volume-title":"https:\/\/static.linaro.org\/connect\/armcca\/presentations\/CCATechEvent-210623-CGT-2.pdf. Referenced","author":"Arm","year":"2021","unstructured":"Arm cca hardware architecture. https:\/\/static.linaro.org\/connect\/armcca\/presentations\/CCATechEvent-210623-CGT-2.pdf. Referenced September 2021 . Arm cca hardware architecture. https:\/\/static.linaro.org\/connect\/armcca\/presentations\/CCATechEvent-210623-CGT-2.pdf. Referenced September 2021."},{"key":"e_1_3_2_1_7_1","volume-title":"https:\/\/www.arm.com\/why-arm\/architecture\/security-features\/arm-confidential-compute-architecture. Referenced","author":"Arm","year":"2021","unstructured":"Arm confidential compute architecture. https:\/\/www.arm.com\/why-arm\/architecture\/security-features\/arm-confidential-compute-architecture. Referenced September 2021 . Arm confidential compute architecture. https:\/\/www.arm.com\/why-arm\/architecture\/security-features\/arm-confidential-compute-architecture. Referenced September 2021."},{"key":"e_1_3_2_1_8_1","volume-title":"https:\/\/developer.arm.com\/documentation\/ddi0504\/c\/. Referenced","author":"Arm","year":"2021","unstructured":"Arm corelink tzc-400 trustzone address space controller technical reference manual. https:\/\/developer.arm.com\/documentation\/ddi0504\/c\/. Referenced September 2021 . Arm corelink tzc-400 trustzone address space controller technical reference manual. https:\/\/developer.arm.com\/documentation\/ddi0504\/c\/. Referenced September 2021."},{"key":"e_1_3_2_1_9_1","volume-title":"https:\/\/developer.arm.com\/tools-and-software\/simulation-models\/fixed-virtual-platforms. Referenced","author":"Arm","year":"2021","unstructured":"Arm fixed virtual platforms. https:\/\/developer.arm.com\/tools-and-software\/simulation-models\/fixed-virtual-platforms. Referenced September 2021 . Arm fixed virtual platforms. https:\/\/developer.arm.com\/tools-and-software\/simulation-models\/fixed-virtual-platforms. Referenced September 2021."},{"key":"e_1_3_2_1_10_1","volume-title":"smmu architecture version 3. https:\/\/developer.arm.com\/documentation\/ihi0070\/latest. Referenced","author":"Arm","year":"2021","unstructured":"Arm system memory management unit architecture specification , smmu architecture version 3. https:\/\/developer.arm.com\/documentation\/ihi0070\/latest. Referenced September 2021 . Arm system memory management unit architecture specification, smmu architecture version 3. https:\/\/developer.arm.com\/documentation\/ihi0070\/latest. Referenced September 2021."},{"key":"e_1_3_2_1_11_1","volume-title":"https:\/\/docs.aws.amazon.com\/vm-import\/latest\/userguide\/vmie_prereqs.html. Referenced","author":"Aws","year":"2021","unstructured":"Aws custom image. https:\/\/docs.aws.amazon.com\/vm-import\/latest\/userguide\/vmie_prereqs.html. Referenced September 2021 . Aws custom image. https:\/\/docs.aws.amazon.com\/vm-import\/latest\/userguide\/vmie_prereqs.html. Referenced September 2021."},{"key":"e_1_3_2_1_12_1","volume-title":"https:\/\/aws.amazon.com\/ec2\/graviton\/. Referenced","author":"Aws","year":"2021","unstructured":"Aws graviton processor. https:\/\/aws.amazon.com\/ec2\/graviton\/. Referenced September 2021 . Aws graviton processor. https:\/\/aws.amazon.com\/ec2\/graviton\/. Referenced September 2021."},{"key":"e_1_3_2_1_13_1","volume-title":"https:\/\/aws.amazon.com\/ec2\/nitro\/nitro-enclaves\/. Referenced","author":"Aws","year":"2021","unstructured":"Aws nitro enclaves. https:\/\/aws.amazon.com\/ec2\/nitro\/nitro-enclaves\/. Referenced September 2021 . Aws nitro enclaves. https:\/\/aws.amazon.com\/ec2\/nitro\/nitro-enclaves\/. Referenced September 2021."},{"key":"e_1_3_2_1_14_1","volume-title":"https:\/\/azure.microsoft.com\/en-us\/solutions\/confidential-compute\/. Referenced","author":"Azure","year":"2021","unstructured":"Azure confidential computing. https:\/\/azure.microsoft.com\/en-us\/solutions\/confidential-compute\/. Referenced September 2021 . Azure confidential computing. https:\/\/azure.microsoft.com\/en-us\/solutions\/confidential-compute\/. Referenced September 2021."},{"key":"e_1_3_2_1_15_1","volume-title":"Count lines of code. https:\/\/github.com\/AlDanial\/cloc. Referenced","year":"2021","unstructured":"cloc : Count lines of code. https:\/\/github.com\/AlDanial\/cloc. Referenced September 2021 . cloc: Count lines of code. https:\/\/github.com\/AlDanial\/cloc. Referenced September 2021."},{"key":"e_1_3_2_1_16_1","volume-title":"https:\/\/lwn.net\/Articles\/486301\/. Referenced","year":"2021","unstructured":"A deep dive into cma. https:\/\/lwn.net\/Articles\/486301\/. Referenced September 2021 . A deep dive into cma. https:\/\/lwn.net\/Articles\/486301\/. Referenced September 2021."},{"key":"e_1_3_2_1_17_1","volume-title":"https:\/\/www.wired.com\/story\/google-cloud-confidential-virtual-machines\/. Referenced","author":"Google","year":"2021","unstructured":"Google cloud confidential virtual machines. https:\/\/www.wired.com\/story\/google-cloud-confidential-virtual-machines\/. Referenced September 2021 . Google cloud confidential virtual machines. https:\/\/www.wired.com\/story\/google-cloud-confidential-virtual-machines\/. Referenced September 2021."},{"key":"e_1_3_2_1_18_1","volume-title":"https:\/\/cloud.google.com\/compute\/confidential-vm\/docs\/how-to-byoi. Referenced","author":"Google","year":"2021","unstructured":"Google custom image. https:\/\/cloud.google.com\/compute\/confidential-vm\/docs\/how-to-byoi. Referenced September 2021 . Google custom image. https:\/\/cloud.google.com\/compute\/confidential-vm\/docs\/how-to-byoi. Referenced September 2021."},{"key":"e_1_3_2_1_19_1","volume-title":"https:\/\/review.trustedfirmware.org\/plugins\/gitiles\/hafnium\/hafnium\/+\/HEAD\/docs\/Architecture.md. Referenced","author":"Hafnium","year":"2021","unstructured":"Hafnium architecture. https:\/\/review.trustedfirmware.org\/plugins\/gitiles\/hafnium\/hafnium\/+\/HEAD\/docs\/Architecture.md. Referenced September 2021 . Hafnium architecture. https:\/\/review.trustedfirmware.org\/plugins\/gitiles\/hafnium\/hafnium\/+\/HEAD\/docs\/Architecture.md. Referenced September 2021."},{"key":"e_1_3_2_1_20_1","volume-title":"https:\/\/www.hisilicon.com\/en\/products\/Kirin\/Kirin-flagship-chips\/Kirin-990. Referenced","author":"Hisilicon","year":"2021","unstructured":"Hisilicon kirin 990 5g. https:\/\/www.hisilicon.com\/en\/products\/Kirin\/Kirin-flagship-chips\/Kirin-990. Referenced September 2021 . Hisilicon kirin 990 5g. https:\/\/www.hisilicon.com\/en\/products\/Kirin\/Kirin-flagship-chips\/Kirin-990. Referenced September 2021."},{"key":"e_1_3_2_1_21_1","volume-title":"https:\/\/www.intel.com\/content\/www\/us\/en\/support\/articles\/000059614\/software\/intel-security-products.html. Referenced","author":"How","year":"2021","unstructured":"How 3rd generation intel\u00ae xeon\u00ae scalable processor platforms support 1 tb epcs. https:\/\/www.intel.com\/content\/www\/us\/en\/support\/articles\/000059614\/software\/intel-security-products.html. Referenced September 2021 . How 3rd generation intel\u00ae xeon\u00ae scalable processor platforms support 1 tb epcs. https:\/\/www.intel.com\/content\/www\/us\/en\/support\/articles\/000059614\/software\/intel-security-products.html. Referenced September 2021."},{"key":"e_1_3_2_1_22_1","volume-title":"https:\/\/www.huaweicloud.com\/en-us\/product\/ecs.html. Referenced","author":"Huawei","year":"2021","unstructured":"Huawei cloud elastic cloud server. https:\/\/www.huaweicloud.com\/en-us\/product\/ecs.html. Referenced September 2021 . Huawei cloud elastic cloud server. https:\/\/www.huaweicloud.com\/en-us\/product\/ecs.html. Referenced September 2021."},{"key":"e_1_3_2_1_23_1","volume-title":"https:\/\/software.intel.com\/content\/dam\/develop\/public\/us\/en\/documents\/intel-sgx-developer-guide.pdf. Referenced","author":"Intel","year":"2021","unstructured":"Intel software guard extensions programming reference, 2014. https:\/\/software.intel.com\/content\/dam\/develop\/public\/us\/en\/documents\/intel-sgx-developer-guide.pdf. Referenced September 2021 . Intel software guard extensions programming reference, 2014. https:\/\/software.intel.com\/content\/dam\/develop\/public\/us\/en\/documents\/intel-sgx-developer-guide.pdf. Referenced September 2021."},{"key":"e_1_3_2_1_24_1","volume-title":"https:\/\/software.intel.com\/content\/dam\/develop\/external\/us\/en\/documents\/intel-tdx-cpu-architectural-specification.pdf. Referenced","author":"Intel\u00ae","year":"2021","unstructured":"Intel\u00ae trust domain cpu architectural extensions. https:\/\/software.intel.com\/content\/dam\/develop\/external\/us\/en\/documents\/intel-tdx-cpu-architectural-specification.pdf. Referenced September 2021 . Intel\u00ae trust domain cpu architectural extensions. https:\/\/software.intel.com\/content\/dam\/develop\/external\/us\/en\/documents\/intel-tdx-cpu-architectural-specification.pdf. Referenced September 2021."},{"key":"e_1_3_2_1_25_1","volume-title":"https:\/\/software.intel.com\/content\/www\/us\/en\/develop\/articles\/intel-trust-domain-extensions.html. Referenced","author":"Intel\u00ae","year":"2021","unstructured":"Intel\u00ae trust domain extensions (intel\u00ae tdx). https:\/\/software.intel.com\/content\/www\/us\/en\/develop\/articles\/intel-trust-domain-extensions.html. Referenced September 2021 . Intel\u00ae trust domain extensions (intel\u00ae tdx). https:\/\/software.intel.com\/content\/www\/us\/en\/develop\/articles\/intel-trust-domain-extensions.html. Referenced September 2021."},{"key":"e_1_3_2_1_26_1","volume-title":"Kernel-based virtual machine. https:\/\/www.linux-kvm.org\/. Referenced","author":"Kvm","year":"2021","unstructured":"Kvm : Kernel-based virtual machine. https:\/\/www.linux-kvm.org\/. Referenced September 2021 . Kvm: Kernel-based virtual machine. https:\/\/www.linux-kvm.org\/. Referenced September 2021."},{"key":"e_1_3_2_1_27_1","volume-title":"Aarch64 virtualization. https:\/\/developer.arm.com\/documentation\/102142\/0100\/Virtualization-Host-Extensions. Referenced","author":"Learn","year":"2021","unstructured":"Learn the architecture : Aarch64 virtualization. https:\/\/developer.arm.com\/documentation\/102142\/0100\/Virtualization-Host-Extensions. Referenced September 2021 . Learn the architecture: Aarch64 virtualization. https:\/\/developer.arm.com\/documentation\/102142\/0100\/Virtualization-Host-Extensions. Referenced September 2021."},{"key":"e_1_3_2_1_28_1","volume-title":"https:\/\/letsencrypt.org\/stats\/. Referenced","author":"Let's","year":"2021","unstructured":"Let's encrypt stats. https:\/\/letsencrypt.org\/stats\/. Referenced September 2021 . Let's encrypt stats. https:\/\/letsencrypt.org\/stats\/. Referenced September 2021."},{"key":"e_1_3_2_1_29_1","volume-title":"https:\/\/www.ibm.com\/blogs\/research\/2020\/11\/amd-sev-ibm-hybrid-cloud\/. Referenced","author":"Leveraging","year":"2021","unstructured":"Leveraging amd sev in the ibm hybrid cloud. https:\/\/www.ibm.com\/blogs\/research\/2020\/11\/amd-sev-ibm-hybrid-cloud\/. Referenced September 2021 . Leveraging amd sev in the ibm hybrid cloud. https:\/\/www.ibm.com\/blogs\/research\/2020\/11\/amd-sev-ibm-hybrid-cloud\/. Referenced September 2021."},{"key":"e_1_3_2_1_30_1","volume-title":"Encryption software market, global forecast to","author":"Marketsandmarkets","year":"2025","unstructured":"Marketsandmarkets : Encryption software market, global forecast to 2025 . https:\/\/www.marketsandmarkets.com\/Market-Reports\/encryption-software-market-227254588.html. Referenced September 2021. Marketsandmarkets: Encryption software market, global forecast to 2025. https:\/\/www.marketsandmarkets.com\/Market-Reports\/encryption-software-market-227254588.html. Referenced September 2021."},{"key":"e_1_3_2_1_31_1","volume-title":"https:\/\/mspoweruser.com\/microsoft-cloud-provider-confidential-virtual-machines\/. Referenced","author":"Microsoft","year":"2021","unstructured":"Microsoft becomes the first major cloud provider to offer confidential virtual machines. https:\/\/mspoweruser.com\/microsoft-cloud-provider-confidential-virtual-machines\/. Referenced September 2021 . Microsoft becomes the first major cloud provider to offer confidential virtual machines. https:\/\/mspoweruser.com\/microsoft-cloud-provider-confidential-virtual-machines\/. Referenced September 2021."},{"key":"e_1_3_2_1_32_1","volume-title":"https:\/\/docs.oracle.com\/en-us\/iaas\/Content\/Compute\/Tasks\/importingcustomimagelinux.htm. Referenced","author":"Oracle","year":"2021","unstructured":"Oracle custom image. https:\/\/docs.oracle.com\/en-us\/iaas\/Content\/Compute\/Tasks\/importingcustomimagelinux.htm. Referenced September 2021 . Oracle custom image. https:\/\/docs.oracle.com\/en-us\/iaas\/Content\/Compute\/Tasks\/importingcustomimagelinux.htm. Referenced September 2021."},{"key":"e_1_3_2_1_33_1","volume-title":"https:\/\/www.amd.com\/system\/files\/TechDocs\/Protecting%20VM%20Register%20State%20with%20SEV-ES.pdf. Referenced","author":"Protecting","year":"2021","unstructured":"Protecting vm register state with sev-es. https:\/\/www.amd.com\/system\/files\/TechDocs\/Protecting%20VM%20Register%20State%20with%20SEV-ES.pdf. Referenced September 2021 . Protecting vm register state with sev-es. https:\/\/www.amd.com\/system\/files\/TechDocs\/Protecting%20VM%20Register%20State%20with%20SEV-ES.pdf. Referenced September 2021."},{"key":"e_1_3_2_1_34_1","volume-title":"stress testing a computer system in various selectable ways. https:\/\/github.com\/ColinIanKing\/stress-ng. Referenced","year":"2021","unstructured":"stress-ng : stress testing a computer system in various selectable ways. https:\/\/github.com\/ColinIanKing\/stress-ng. Referenced September 2021 . stress-ng: stress testing a computer system in various selectable ways. https:\/\/github.com\/ColinIanKing\/stress-ng. Referenced September 2021."},{"key":"e_1_3_2_1_35_1","volume-title":"https:\/\/www.intel.com\/content\/dam\/www\/public\/us\/en\/documents\/white-papers\/supporting-intel-sgx-on-mulit-socket-platforms.pdf. Referenced","author":"Supporting","year":"2021","unstructured":"Supporting intel\u00ae sgx on multi-socket platforms. https:\/\/www.intel.com\/content\/dam\/www\/public\/us\/en\/documents\/white-papers\/supporting-intel-sgx-on-mulit-socket-platforms.pdf. Referenced September 2021 . Supporting intel\u00ae sgx on multi-socket platforms. https:\/\/www.intel.com\/content\/dam\/www\/public\/us\/en\/documents\/white-papers\/supporting-intel-sgx-on-mulit-socket-platforms.pdf. Referenced September 2021."},{"key":"e_1_3_2_1_36_1","volume-title":"level 2 revision 116, 1 march","author":"Tpm","year":"2011","unstructured":"Tpm main specification version 1.2 , level 2 revision 116, 1 march 2011 , trusted computing group. https:\/\/trustedcomputinggroup.org\/wp-content\/uploads\/TPM-Main-Part-3-Commands_v1.2_rev116_01032011.pdf. Referenced September 2021. Tpm main specification version 1.2, level 2 revision 116, 1 march 2011, trusted computing group. https:\/\/trustedcomputinggroup.org\/wp-content\/uploads\/TPM-Main-Part-3-Commands_v1.2_rev116_01032011.pdf. Referenced September 2021."},{"key":"e_1_3_2_1_37_1","volume-title":"Exploiting trustzone tees. https:\/\/googleprojectzero.blogspot.com\/2017\/07\/trust-issues-exploiting-trustzone-tees.html. Referenced","author":"Trust","year":"2021","unstructured":"Trust issues : Exploiting trustzone tees. https:\/\/googleprojectzero.blogspot.com\/2017\/07\/trust-issues-exploiting-trustzone-tees.html. Referenced September 2021 . Trust issues: Exploiting trustzone tees. https:\/\/googleprojectzero.blogspot.com\/2017\/07\/trust-issues-exploiting-trustzone-tees.html. Referenced September 2021."},{"key":"e_1_3_2_1_38_1","volume-title":"https:\/\/wiki.xenproject.org\/wiki\/Xen_ARM_with_Virtualization_Extensions. Referenced","author":"Xen","year":"2021","unstructured":"Xen arm with virtualization extensions. https:\/\/wiki.xenproject.org\/wiki\/Xen_ARM_with_Virtualization_Extensions. Referenced September 2021 . Xen arm with virtualization extensions. https:\/\/wiki.xenproject.org\/wiki\/Xen_ARM_with_Virtualization_Extensions. Referenced September 2021."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378468"},{"key":"e_1_3_2_1_40_1","volume-title":"Proceedings of the 12th USENIX Conference on Operating Systems Design and Implementation","author":"Arnautov S.","year":"2016","unstructured":"Arnautov , S. , Trach , B. , Gregor , F. , Knauth , T. , Martin , A. , Priebe , C. , Lind , J. , Muthukumaran , D. , O'Keeffe , D. , Stillwell , M. L. , Goltzsche , D. , Eyers , D. , Kapitza , R. , Pietzuch , P. , and Fetzer , C . Scone: Secure linux containers with intel sgx . In Proceedings of the 12th USENIX Conference on Operating Systems Design and Implementation ( Berkeley, CA, USA , 2016 ). Arnautov, S., Trach, B., Gregor, F., Knauth, T., Martin, A., Priebe, C., Lind, J., Muthukumaran, D., O'Keeffe, D., Stillwell, M. L., Goltzsche, D., Eyers, D., Kapitza, R., Pietzuch, P., and Fetzer, C. Scone: Secure linux containers with intel sgx. In Proceedings of the 12th USENIX Conference on Operating Systems Design and Implementation (Berkeley, CA, USA, 2016)."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/1165389.945462"},{"key":"e_1_3_2_1_42_1","first-page":"423","volume-title":"Proceedings of the 9th USENIX Conference on Operating Systems Design and Implementation (USA, 2010), OSDI'10, USENIX Association","author":"Ben-Yehuda M.","unstructured":"Ben-Yehuda , M. , Day , M. D. , Dubitzky , Z. , Factor , M. , Har'El , N. , Gordon , A. , Liguori , A. , Wasserman , O. , and Yassour , B . -A. The turtles project: Design and implementation of nested virtualization . In Proceedings of the 9th USENIX Conference on Operating Systems Design and Implementation (USA, 2010), OSDI'10, USENIX Association , p. 423 -- 436 . Ben-Yehuda, M., Day, M. D., Dubitzky, Z., Factor, M., Har'El, N., Gordon, A., Liguori, A., Wasserman, O., and Yassour, B.-A. The turtles project: Design and implementation of nested virtualization. In Proceedings of the 9th USENIX Conference on Operating Systems Design and Implementation (USA, 2010), OSDI'10, USENIX Association, p. 423--436."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00061"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIT.2018.8352425"},{"key":"e_1_3_2_1_46_1","volume-title":"2017 USENIX Annual Technical Conference (USENIX ATC 17)","author":"Dall C.","year":"2017","unstructured":"Dall , C. , Li , S.-W. , and Nieh , J . Optimizing the design and implementation of the linux ARM hypervisor . In 2017 USENIX Annual Technical Conference (USENIX ATC 17) (Santa Clara, CA , July 2017 ), USENIX Association, pp. 221--233. Dall, C., Li, S.-W., and Nieh, J. Optimizing the design and implementation of the linux ARM hypervisor. In 2017 USENIX Annual Technical Conference (USENIX ATC 17) (Santa Clara, CA, July 2017), USENIX Association, pp. 221--233."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/2654822.2541946"},{"key":"e_1_3_2_1_48_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Ahmadi M.","year":"2021","unstructured":"farkhani, R. M., Ahmadi , M. , and Lu , L . Ptauth: Temporal memory safety via robust points-to authentication . In 30th USENIX Security Symposium (USENIX Security 21) ( Aug. 2021 ), USENIX Association. farkhani, R. M., Ahmadi, M., and Lu, L. Ptauth: Temporal memory safety via robust points-to authentication. In 30th USENIX Security Symposium (USENIX Security 21) (Aug. 2021), USENIX Association."},{"key":"e_1_3_2_1_49_1","first-page":"287","volume-title":"Proceedings of the 26th Symposium on Operating Systems Principles (New York, NY, USA, 2017), SOSP '17, Association for Computing Machinery","author":"Ferraiuolo A.","unstructured":"Ferraiuolo , A. , Baumann , A. , Hawblitzel , C. , and Parno , B . Komodo: Using verification to disentangle secure-enclave hardware from software . In Proceedings of the 26th Symposium on Operating Systems Principles (New York, NY, USA, 2017), SOSP '17, Association for Computing Machinery , p. 287 -- 305 . Ferraiuolo, A., Baumann, A., Hawblitzel, C., and Parno, B. Komodo: Using verification to disentangle secure-enclave hardware from software. In Proceedings of the 26th Symposium on Operating Systems Principles (New York, NY, USA, 2017), SOSP '17, Association for Computing Machinery, p. 287--305."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.24"},{"key":"e_1_3_2_1_51_1","first-page":"653","volume-title":"12th USENIX Symposium on Operating Systems Design and Implementation, OSDI 2016","author":"Gu R.","year":"2016","unstructured":"Gu , R. , Shao , Z. , Chen , H. , Wu , X. N. , Kim , J. , Sj\u00f6berg , V. , and Costanzo , D . Certikos: An extensible architecture for building certified concurrent OS kernels . In 12th USENIX Symposium on Operating Systems Design and Implementation, OSDI 2016 , Savannah, GA, USA , November 2-4, 2016 (2016), K. Keeton and T. Roscoe, Eds., USENIX Association, pp. 653 -- 669 . Gu, R., Shao, Z., Chen, H., Wu, X. N., Kim, J., Sj\u00f6berg, V., and Costanzo, D. Certikos: An extensible architecture for building certified concurrent OS kernels. In 12th USENIX Symposium on Operating Systems Design and Implementation, OSDI 2016, Savannah, GA, USA, November 2-4, 2016 (2016), K. Keeton and T. Roscoe, Eds., USENIX Association, pp. 653--669."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jcp.2012.11.031"},{"key":"e_1_3_2_1_53_1","first-page":"541","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Hua Z.","year":"2017","unstructured":"Hua , Z. , Gu , J. , Xia , Y. , Chen , H. , Zang , B. , and Guan , H . vtz: Virtualizing ARM trustzone . In 26th USENIX Security Symposium (USENIX Security 17) (Vancouver, BC, Aug. 2017 ), USENIX Association , pp. 541 -- 556 . Hua, Z., Gu, J., Xia, Y., Chen, H., Zang, B., and Guan, H. vtz: Virtualizing ARM trustzone. In 26th USENIX Security Symposium (USENIX Security 17) (Vancouver, BC, Aug. 2017), USENIX Association, pp. 541--556."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447786.3456243"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3324989.3325722"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40517-4_16"},{"key":"e_1_3_2_1_57_1","first-page":"189","volume-title":"21st USENIX Security Symposium (USENIX Security 12)","author":"Kim T.","year":"2012","unstructured":"Kim , T. , Peinado , M. , and Mainar-Ruiz , G . STEALTHMEM: Systemlevel protection against cache-based side channel attacks in the cloud . In 21st USENIX Security Symposium (USENIX Security 12) (Bellevue, WA, Aug. 2012 ), USENIX Association , pp. 189 -- 204 . Kim, T., Peinado, M., and Mainar-Ruiz, G. STEALTHMEM: Systemlevel protection against cache-based side channel attacks in the cloud. In 21st USENIX Security Symposium (USENIX Security 12) (Bellevue, WA, Aug. 2012), USENIX Association, pp. 189--204."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/1629575.1629596"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/3064176.3064192"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2019.2910861"},{"key":"e_1_3_2_1_61_1","first-page":"1257","volume-title":"Proceedings of the 28th USENIX Conference on Security Symposium (USA, 2019), SEC'19, USENIX Association","author":"Li M.","unstructured":"Li , M. , Zhang , Y. , Lin , Z. , and Solihin , Y . Exploiting unprotected i\/o operations in amd's secure encrypted virtualization . In Proceedings of the 28th USENIX Conference on Security Symposium (USA, 2019), SEC'19, USENIX Association , p. 1257 -- 1272 . Li, M., Zhang, Y., Lin, Z., and Solihin, Y. Exploiting unprotected i\/o operations in amd's secure encrypted virtualization. In Proceedings of the 28th USENIX Conference on Security Symposium (USA, 2019), SEC'19, USENIX Association, p. 1257--1272."},{"key":"e_1_3_2_1_62_1","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Li S.-W.","year":"2019","unstructured":"Li , S.-W. , Koh , J. S. , and Nieh , J . Protecting cloud virtual machines from hypervisor and host operating system exploits . In 28th USENIX Security Symposium (USENIX Security 19) (Santa Clara, CA , Aug. 2019 ). Li, S.-W., Koh, J. S., and Nieh, J. Protecting cloud virtual machines from hypervisor and host operating system exploits. In 28th USENIX Security Symposium (USENIX Security 19) (Santa Clara, CA, Aug. 2019)."},{"key":"e_1_3_2_1_63_1","first-page":"3953","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Li S.-W.","year":"2021","unstructured":"Li , S.-W. , Li , X. , Gu , R. , Nieh , J. , and Hui , J. Z . Formally verified memory protection for a commodity multiprocessor hypervisor . In 30th USENIX Security Symposium (USENIX Security 21) ( Aug. 2021 ), USENIX Association , pp. 3953 -- 3970 . Li, S.-W., Li, X., Gu, R., Nieh, J., and Hui, J. Z. Formally verified memory protection for a commodity multiprocessor hypervisor. In 30th USENIX Security Symposium (USENIX Security 21) (Aug. 2021), USENIX Association, pp. 3953--3970."},{"key":"e_1_3_2_1_64_1","first-page":"2","volume-title":"Proceedings of the 15th ACM SIGPLAN\/SIGOPS International Conference on Virtual Execution Environments (New York, NY, USA, 2019), VEE 2019, Association for Computing Machinery","author":"Li W.","unstructured":"Li , W. , Xia , Y. , Lu , L. , Chen , H. , and Zang , B . Teev: Virtualizing trusted execution environments on mobile platforms . In Proceedings of the 15th ACM SIGPLAN\/SIGOPS International Conference on Virtual Execution Environments (New York, NY, USA, 2019), VEE 2019, Association for Computing Machinery , p. 2 -- 16 . Li, W., Xia, Y., Lu, L., Chen, H., and Zang, B. Teev: Virtualizing trusted execution environments on mobile platforms. In Proceedings of the 15th ACM SIGPLAN\/SIGOPS International Conference on Virtual Execution Environments (New York, NY, USA, 2019), VEE 2019, Association for Computing Machinery, p. 2--16."},{"key":"e_1_3_2_1_65_1","first-page":"201","volume-title":"Proceedings of the 26th Symposium on Operating Systems Principles (New York, NY, USA, 2017), SOSP '17, Association for Computing Machinery","author":"Lim J. T.","unstructured":"Lim , J. T. , Dall , C. , Li , S.-W. , Nieh , J. , and Zyngier , M . Neve: Nested virtualization extensions for arm . In Proceedings of the 26th Symposium on Operating Systems Principles (New York, NY, USA, 2017), SOSP '17, Association for Computing Machinery , p. 201 -- 217 . Lim, J. T., Dall, C., Li, S.-W., Nieh, J., and Zyngier, M. Neve: Nested virtualization extensions for arm. In Proceedings of the 26th Symposium on Operating Systems Principles (New York, NY, USA, 2017), SOSP '17, Association for Computing Machinery, p. 201--217."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542275.1542309"},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/3173162.3173175"},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2018.2846742"},{"key":"e_1_3_2_1_69_1","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Mi Z.","year":"2020","unstructured":"Mi , Z. , Li , D. , Chen , H. , Zang , B. , and Haibing , G . (mostly) exitless VM protection from untrusted hypervisor through disaggregated nested virtualization . In 29th USENIX Security Symposium (USENIX Security 20) (Boston, MA, Aug. 2020 ), USENIX Association. Mi, Z., Li, D., Chen, H., Zang, B., and Haibing, G. (mostly) exitless VM protection from untrusted hypervisor through disaggregated nested virtualization. In 29th USENIX Security Symposium (USENIX Security 20) (Boston, MA, Aug. 2020), USENIX Association."},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/3302424.3303946"},{"key":"e_1_3_2_1_71_1","first-page":"269","volume-title":"2019 USENIX Annual Technical Conference (USENIX ATC 19)","author":"Narayanan V.","year":"2019","unstructured":"Narayanan , V. , Balasubramanian , A. , Jacobsen , C. , Spall , S. , Bauer , S. , Quigley , M. , Hussain , A. , Younis , A. , Shen , J. , Bhattacharyya , M. , and Burtsev , A . Lxds: Towards isolation of kernel subsystems . In 2019 USENIX Annual Technical Conference (USENIX ATC 19) (Renton, WA, July 2019 ), USENIX Association , pp. 269 -- 284 . Narayanan, V., Balasubramanian, A., Jacobsen, C., Spall, S., Bauer, S., Quigley, M., Hussain, A., Younis, A., Shen, J., Bhattacharyya, M., and Burtsev, A. Lxds: Towards isolation of kernel subsystems. In 2019 USENIX Annual Technical Conference (USENIX ATC 19) (Renton, WA, July 2019), USENIX Association, pp. 269--284."},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/3064176.3064219"},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1109\/CCGrid.2012.84"},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/3291047"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1145\/361011.361073"},{"key":"e_1_3_2_1_76_1","first-page":"841","volume-title":"Proceedings of the 25th USENIX Conference on Security Symposium (USA, 2016), SEC'16, USENIX Association","author":"Raj H.","unstructured":"Raj , H. , Saroiu , S. , Wolman , A. , Aigner , R. , Cox , J. , England , P. , Fenner , C. , Kinshumann , K. , Loeser , J. , Mattoon , D. , Nystrom , M. , Robinson , D. , Spiger , R. , Thom , S. , and Wooten , D . Ftpm: A software-only implementation of a tpm chip . In Proceedings of the 25th USENIX Conference on Security Symposium (USA, 2016), SEC'16, USENIX Association , p. 841 -- 856 . Raj, H., Saroiu, S., Wolman, A., Aigner, R., Cox, J., England, P., Fenner, C., Kinshumann, K., Loeser, J., Mattoon, D., Nystrom, M., Robinson, D., Spiger, R., Thom, S., and Wooten, D. Ftpm: A software-only implementation of a tpm chip. In Proceedings of the 25th USENIX Conference on Security Symposium (USA, 2016), SEC'16, USENIX Association, p. 841--856."},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/1272366.1272390"},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSPEC.2020.9099920"},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSNW.2011.5958812"},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23500"},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1145\/1229428.1229452"},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2013.6522323"},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2017.10"},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1145\/2043556.2043576"},{"key":"e_1_3_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378507"},{"key":"e_1_3_2_1_86_1","volume-title":"Sok: Hardware security support for trustworthy execution. CoRR abs\/1910.04957","author":"Zhao L.","year":"2019","unstructured":"Zhao , L. , Shuang , H. , Xu , S. , Huang , W. , Cui , R. , Bettadpur , P. , and Lie , D . Sok: Hardware security support for trustworthy execution. CoRR abs\/1910.04957 ( 2019 ). Zhao, L., Shuang, H., Xu, S., Huang, W., Cui, R., Bettadpur, P., and Lie, D. Sok: Hardware security support for trustworthy execution. CoRR abs\/1910.04957 (2019)."}],"event":{"name":"SOSP '21: ACM SIGOPS 28th Symposium on Operating Systems Principles","location":"Virtual Event Germany","acronym":"SOSP '21","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems","USENIX Assoc USENIX Assoc"]},"container-title":["Proceedings of the ACM SIGOPS 28th Symposium on Operating Systems Principles"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3477132.3483554","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3477132.3483554","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:49:15Z","timestamp":1750193355000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3477132.3483554"}},"subtitle":["Hardware-isolated Confidential Virtual Machines for ARM"],"short-title":[],"issued":{"date-parts":[[2021,10,26]]},"references-count":85,"alternative-id":["10.1145\/3477132.3483554","10.1145\/3477132"],"URL":"https:\/\/doi.org\/10.1145\/3477132.3483554","relation":{},"subject":[],"published":{"date-parts":[[2021,10,26]]},"assertion":[{"value":"2021-10-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}