Search papers, labs, and topics across Lattice.
This paper introduces NACRE, a RISC-V hardware-software co-design that enhances the security of Linux containers by creating a native confidential container architecture. By decoupling the host's resource management authority from its access to protected state, NACRE allows for secure container operations without the overhead of separate protection contexts. The prototype demonstrates performance metrics that remain close to the baseline while ensuring robust security for containerized applications.
NACRE achieves secure containerization without sacrificing performance, maintaining syscall metrics within 3.5% of the baseline while enhancing confidentiality.
Linux containers achieve high density and fast lifecycle operations by sharing the host kernel, but this design also lets a compromised host inspect or modify container state. Existing confidential-computing systems protect an enclave address space or an entire guest operating system, while recent container-granularity systems still add a separate protection context. These abstractions do not make a dynamic group of host-managed Linux processes the architectural protection unit. This paper presents NACRE, a RISC-V hardware-software co-design for native confidential containers. Its key insight is to separate the host's authority to manage resources from its authority to access or commit protected state. Hardware-recognized container identities direct protected traps to an isolated S-mode agent, while an M-mode monitor commits security- sensitive identity, mapping, and page transitions. The agent delegates services to host Linux without changing satp; services that neither access private bytes nor modify protected state also avoid M-mode. We prototype NACRE by extending QEMU, OpenSBI, Linux, a trusted agent, and runc. The prototype implements the single-container private-memory substrate and covered launch, fault, fork/COW, user-access, and teardown paths. Across five lmbench syscall and pipe metrics, the three-run means remain within 3.5% of the runc-origin baseline. With the eight nginx object-size means weighted equally, aggregate throughput is 1.9% lower.