AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
Article Link
Collect
Submit Manuscript
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Regular Paper

Harmonizing Security and Performance in Microkernel File Servers

Institute of Parallel and Distributed Systems, School of Electronic Information and Electrical Engineering Shanghai Jiao Tong University, Shanghai 200240, China
Show Author Information

Abstract

Microkernel OSes separate OS functionalities, including file systems and device drivers, into different user-level services, which mitigates the problem of lacking isolation in monolithic OSes. Nevertheless, from the perspective of applications, compromised services may still threaten applications’ security. Specifically, attackers can utilize vulnerabilities in file systems and disk drivers to leak or manipulate applications’ file content. The key problem is that de-privileging OS services from the kernel level to the user level does not mean the reduction of applications’ trusted computing base (TCB), and applications still need to trust all the required system services. This paper shows a case for providing the file service to applications with minimum TCB on microkernel OSes. Observing that file services actually do not need to access concrete file content, we propose a mechanism named Mirage, which deprives their privilege of accessing file content while preserving their management capability. Mirage efficiently protects the confidentiality and integrity of application files from untrusted services. The evaluation demonstrates that Mirage outperforms an encryption-based mechanism by up to 128% for IO-intensive workloads.

Electronic Supplementary Material

Download File(s)
JCST-2309-13762-Highlights.pdf (249.3 KB)

References

【1】
【1】
 
 
Journal of Computer Science and Technology
Pages 464-481

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Li W-T, Wang Z-X, Gu J-Y, et al. Harmonizing Security and Performance in Microkernel File Servers. Journal of Computer Science and Technology, 2025, 40(2): 464-481. https://doi.org/10.1007/s11390-025-3762-3

1032

Views

0

Crossref

0

Web of Science

1

Scopus

0

CSCD

Received: 11 September 2023
Accepted: 14 January 2025
Published: 31 March 2025
© Institute of Computing Technology, Chinese Academy of Sciences 2025