Главная
Study mode:
on
1
Intro
2
Imperial College London
3
Clouds: Isolation vs. Sharing
4
VMs: Strong, Heavyweight Isolation
5
Containers: Weak, Lightweight Isolation
6
VMs & Containers: The MMU Tax
7
CHERI Capabilities
8
Challenges for Cloud Stacks with Hardware Capabilities
9
CVM: Intra-Process VM-like Abstraction
10
Isolation/Sharing for Legacy Cloud Apps?
11
Support for Native Software
12
Small-TCB OS Functionality
13
IPC Interfaces Using Capabilities
14
CAP-VM Prototype
15
Comparing with IPC Mechanisms
Description:
Explore a 14-minute conference talk from OSDI '22 that introduces CAP-VMs, a novel approach to capability-based isolation and sharing in cloud environments. Delve into the challenges of balancing application component isolation with efficient data sharing on physical hosts. Learn how forthcoming CPUs with hardware support for memory capabilities offer new opportunities for fine-grained isolation and sharing. Discover the concept of cVMs, a VM-like abstraction that utilizes memory capabilities to isolate components while supporting efficient data exchange. Examine the two capability-based primitives for cross-cVM communication and their implementation using CHERI RISC-V capabilities. Gain insights into how this approach can improve cloud stack security and performance, demonstrated through prototype implementations with Redis and Python services.

CAP-VMs - Capability-Based Isolation and Sharing in the Cloud

USENIX
Add to list
0:00 / 0:00