US 6151610A
· Senn et al.
· 2000
[cited by applicant]
US 9177153B1
· Perrig
· 2015
[cited by examiner]
US 9317490B2
· Cook
· 2016
[cited by applicant]
US 9442752B1
· Roth et al.
· 2016
[cited by applicant]
US 9792222B2
· Sahita
· 2017
[cited by examiner]
US 9983894B2
· Horovitz et al.
· 2018
[cited by applicant]
J. Elwell, D. Evtyushkin, D. Ponomarev, N. Abu-Ghazaleh and R. Riley, “Hardening extended memory access control schemes with self-verified address spaces,” 2017 IEEE/ACM International Conference on Computer-Aided Design…
[cited by examiner]
D. Evtyushkin, J. Elwell, M. Ozsoy, D. Ponomarev, N. A. Ghazaleh and R. Riley, “Flexible Hardware-Managed Isolated Execution: Architecture, Software Support and Applications,” in IEEE Transactions on Dependable and Secu…
[cited by examiner]
John Criswell, Nathan Dautenhahn, Vikram Adve, “Virtual ghost: protecting applications from hostile operating systems”, ASPLOS ' 14: Proceedings of the 19th international conference on Architectural support for programm…
[cited by examiner]
J. Jang et al., “PrivateZone: Providing a Private Execution Environment Using ARM TrustZone,” in IEEE Transactions on Dependable and Secure Computing, vol. 15, No. 5, pp. 797-810, Sep. 1-Oct. 2018 (Year: 2018).
[cited by examiner]
Acharya, A. and Raje, M., “MAPbox: Using Parameterized Behavior Classes to Confine Applications”, In Proceedings of the 9th USENIX Security Symposium (SSYM '00), Denver, CO, US,, Aug. 14-17, 2000, pp. 1-19.
[cited by applicant]
Adobe Systems Incorporated, “Security Updates Available for Adobe Reader and Acrobat Versions 9 and Earlier”, Mar. 24, 2009, available at: http://www.adobe.com/support/security/advisories/apsa09-01.html, pp. 1-3.
[cited by applicant]
Amazon Web Services, Inc., “Building an Enclave Image File”, last accessed Aug. 16, 2024, available at: https://docs.aws.amazon.com/enclaves/ latest/user/building-eif.html, pp. 1-3.
[cited by applicant]
Amazon Web Services, Inc., “The Security Design of the AWS Nitro System: AWS Whitepaper”, Feb. 15, 2024, available at: https://docs.aws.amazon.com/pdfs/whitepapers/latest/security-design-of-aws-nitro-system/security-des…
[cited by applicant]
ARM Ltd., “ARM CCA Security Model 1.0”, Aug. 2021, available at: https://developer.arm.com/documentation/ DEN0096/A_a/?lang=en, pp. 1-68.
[cited by applicant]
ARM Ltd., “Arm Confidential Compute Architecture”, last accessed Oct. 19, 2021, available at: https://www.arm.com/ why-arm/architecture/security-features/ arm-confidential-compute-architecture, pp. 1-11.
[cited by applicant]
ARM Ltd., “Arm Neoverse N1 Core Technical Reference Manual”, Apr. 2019, available at: https://developer.arm.com/documentation/100616/0400/, pp. 1-4.
[cited by applicant]
ARM Ltd., “ARM Security Technology: Building a Secure System using TrustZone Technology”, Technical Report, Apr. 2009, pp. 1-108.
[cited by applicant]
ARM Ltd., “Realm Management Extension”, Jun. 2021, available at: https://developer.arm.com/documentation/den0126/latest/, p. 1.3.
[cited by applicant]
ARM Ltd., “Virtualization Host Extensions”, Jan. 2019, available at: https://developer.arm.com/documentation/ 102142/0100/Virtualization-Host-Extensions, pp. 1-4.
[cited by applicant]
Arnautov, S., et al., “SCONE: Secure Linux Containers with Intel SGX”, In Proceedings of the 12th USENIX Conference on Operating Systems Design and Implementation (OSDI 2016), Savannah, GA, US, Nov. 2-4, 2016, pp. 689-7…
[cited by applicant]
Azab, A.M., et al., “Sice: A hardware-level strongly isolated computing environment for x86 multi-core platforms”, In Proceedings of the 18th ACM Conference on Computer and Communications Security (CCS 2011), Oct. 17-21…
[cited by applicant]
Backes, M., et al., “Preventing Side-Channel Leaks in Web Traffic: A Formal Approach”, In 20th Annual Network and Distributed System Security Symposium (NDSS 2013), San Diego, CA, US, Feb. 24-27, 2013, pp. 1-17.
[cited by applicant]
Bajaj, S., et al., “TrustedDB: a Trusted Hardware Based Database with Privacy and Data Confidentiality”, In Proceedings of the 2011 ACM SIGMOD International Conference on Management of Data, Athens, GR, Jun. 12-16, 2011…
[cited by applicant]
Baratto, R., et al., “THINC: A Remote Display Architecture for Thin-Client Computing”, Technical Report CUCS-027-04, Columbia University, Jul. 2004, pp. 1-15.
[cited by applicant]
Baumann, A., et al., “Shielding Applications from an Untrusted Cloud with Haven”, In Proceedings of the 11th USENIX Conference on Operating Systems Design and Implementation (OSDI 2014), Broomfield, CO, US, Oct. 6-8, 20…
[cited by applicant]
Bellard, F., “QEMU, a Fast and Portable Dynamic Translator”, In Proceedings of USENIX Annual Technical Conference, Anaheim, California, US, Apr. 10-Apr. 15, 2005, pp. 41-46.
[cited by applicant]
Berman, A., et al., “TRON: Process-Specific File Protection for the UNIX Operating System”, In Proceedings of the USENIX Winter Technical Conference (TCON '95), New Orleans, LA, US, Jan. 16-20, 1995, pp. 165-175.
[cited by applicant]
Bitdefender, “Trojan.PWS.ChromeInject.B”, Nov. 2008, available at: http://www.bitdefender.com/VIRUS-1000451-en--Trojan-PWS-ChromeInject-B.html, pp. 1-3.
[cited by applicant]
Brasser, F., “Sanctuary: Arming trustzone with user-space enclaves”, In Proceedings 2019 Network and Distributed System Security Symposium, San Diego, CA, US, Feb. 24-27, 2019, pp. 1-15.
[cited by applicant]
Brasser, F., et al., “Special Session: Advances and Throwbacks in Hardware-Assisted Security”, IEEE, In Proceedings of 2018 International Conference on Compilers, Architectures and Synthesis for Embedded Systems (CASES)…
[cited by applicant]
Business Wire, “Research and Markets: Global Encryption Software Market (Usage, Vertical and Geography)—Size, Global Trends, Company Profiles, Segmentation and Forecast, 2013-2020 ”, Feb. 11, 2015, pp. 1-3.
[cited by applicant]
Chan, H., et al., “Random Key Predistribution Schemes for Sensor Networks”, IEEE, In Proceedings of the 2003 Symposium on Security and Privacy, Berkeley, CA, US, May 11-14, 2003, pp. 197-213.
[cited by applicant]
Checkoway, S. and Shacham, H., “lago Attacks: Why the System Call API is a Bad Untrusted RPC Interface”, In Proceedings of the 18th International Conference on Architectural Support for Programming Languages and Operati…
[cited by applicant]
Chen, H., et al., “Tamper-Resistant Execution in an Untrusted Operating System Using A Virtual Machine Monitor”, Technical Report PPITR-2007-08001, Parallel Processing Institute, Fudan University, Aug. 2007, pp. 1-17.
[cited by applicant]
Chen, X., et al., “Overshadow: A Virtualization-based Approach to Retrofitting Protection in Commodity Operating Systems”, In Proc. of the 13th Intl. Conf. on Architectural Support for Programming Languages and Operatin…
[cited by applicant]
Cheng, Y., et al., “Efficient Virtualization-Based Application Protection against Untrusted Operating System”, In Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security (ASIACCS 2015)…
[cited by applicant]
Cooper, B. F., et al., “Benchmarking Cloud Serving Systems with YCSB”, In Proceedings of the 1st ACM Symposium on Cloud Computing, Indianapolis, IN, US, Jun. 10-11, 2010, pp. 143-154.
[cited by applicant]
Costan, V., et al., “Sanctum: Minimal hardware extensions for strong software isolation”, In 25th USENIX Security Symposium (USENIX Security 2016), Austin, TX, US, Aug. 10-12, 2016, pp. 857-874.
[cited by applicant]
Cowan, C et al., “SubDomain: Parsimonious Server Security”, In Proceedings of the 14th USENIX System Administration Conference (LISA '00), New Orleans, LA, US, Dec. 3-8, 2000, pp. 341-354.
[cited by applicant]
Cui, J., et al., “Dynamic Binary Translation for SGX Enclaves”, In ACM Transactions on Privacy and Security, vol. 25, No. 4, Nov. 2022, pp. 1-40.
[cited by applicant]
Dall, C., et al., “ARM Virtualization: Performance and Architectural Implications”, In Proceedings of the 43rd International Symposium on Computer Architecture (ISCA 2016), Seoul, KR, Jun. 18-22, 2016, pp. 304-316.
[cited by applicant]
Dall, C., et al., “Optimizing the Design and Implementation of the Linux ARM Hypervisor”, In Proceedings of the 2017 USENIX Annual Technical Conference (USENIX ATC '17), Santa Clara, CA, US, Jul. 12-14, 2017, pp. 1-15.
[cited by applicant]
Docker, Inc., “Empowering App Development for Developers—Docker”, last accessed Aug. 16, 2024, available at: https://www.docker.com, pp. 1-11.
[cited by applicant]
Ferraiuolo, A., et al., “Komodo: Using Verification to Disentangle Secure-Enclave Hardware from Software”, In Proceedings of the 26th Symposium on Operating Systems Principles, Shanghai, CN, Oct. 28, 2017, pp. 287-305.
[cited by applicant]
Fox, A.C.J., et al., “A Verification Methodology for the Arm Confidential Computing Architecture: From a Secure Specification to Safe Implementations”, In Proceedings of hte ACM on Programming Languages, vol. 7, No. 88,…
[cited by applicant]
Gettys, J. and Scheifler, R.W., “Xlib-C Language X Interface”, X Consortium, Inc., (month unknown) 1996, pp. 1-466.
[cited by applicant]
Gilmore, M., “-10 Day CERT Advisory on PDF Files”, Jun. 13, 2003, available at: http://seclists.org/fulldisclosure/2003/Jun/0463.html, pp. 1-3.
[cited by applicant]
Github, “Confidential Containers”, last accessed Aug. 19, 2024, available at: https://github.com/confidential-containers, pp. 1-5.
[cited by applicant]
Github, “foreign-dlopen”, last accessed Aug. 19, 2024, available at: https://github.com/pfalcon/foreign-dlopen, pp. 1-5.
[cited by applicant]
Github, “Open Enclave”, last accessed Aug. 19, 2024, available at: https://github.com/openenclave/openenclave, pp. 1-4.
[cited by applicant]
Github, “Sysbench”, v1.0.20, last accessed Aug. 19, 2024, available at: https://github.com/akopytov/sysbench, pp. 1-7.
[cited by applicant]
Google, Inc., “GoogleContainerTools/distroless: Language Focused Docker Images, Minus the Operating System”, last accessed Aug. 19, 2024, available at: https://github.com/GoogleContainerTools/distroless, pp. 1-8.
[cited by applicant]
Google, Inc., “gVisor: Application Kernel for Containers”, last accessed Aug. 16, 2024, available at: https://github.com/google/gvisor, pp. 1-5.
[cited by applicant]
Google, Inc., “HTTPS encryption on the web—Google Transparency Report”, last accessed Aug. 19, 2024, available at: https://transparencyreport. google.com/https/overview, pp. 1-6.
[cited by applicant]
Gu, G., et al., “BotSniffer: Detecting Botnet Command and Control Channels in Network Traffic”, In Proceedings of the 15th Annual Network and Distributed System Security Symposium, San Diego, CA, US, Feb. 10-13, 2008, p…
[cited by applicant]
Gu, R., et al., “CertiKOS: An Extensible Architecture for Building Certified Concurrent OS Kernels”, In Proceedings of the 12th Symposium on Operating Systems Design and Implementation, Savannah, GA, US, Nov. 2-4, 2016,…
[cited by applicant]
Guan, L., et al., “Trustshadow: Secure Execution of Unmodified Applications with Arm Trustzone”, In Proceedings of the 15th Annual International Conference on Mobile Systems, Applications, and Services (MobiSys 2017, Ni…
[cited by applicant]
Hajnoczi, S., “An Updated Overview of the QEMU Storage Stack”, Presentation, IBM Linux Technology Center, Jun. 2011, pp. 1-26.
[cited by applicant]
Heiser, G. and Leslie, B. “The OKL4 Microvisor: Convergence Point of Microkernels and Hypervisors”, In Proceedings of the 1st ACM Asia-pacific Workshop on Workshop on Systems (APSys 2010), New Delhi, IN, Aug. 30, 2010, …
[cited by applicant]
Hofmann, O.S., et al., “InkTag: Secure Applications on an Untrusted Operating System”, In Proceedings of the 18th International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS…
[cited by applicant]
Hua, Z., et al., “TZ-Container: Protecting Container from Untrusted OS with ARMTrustZone”, In Science China Information Sciences, vol. 64, Aug. 2021, pp. 1-17.
[cited by applicant]
Hykes, S., “Introducing runC: A lightweight Universal Container Runtime”, availabl at: https://www.docker.com/blog/runc/, Jun. 22, 2015, pp. 1-7.
[cited by applicant]
Intel Corporation, “Intel Software Guard Extensions Programming Reference”, available at: https://software.intel.com/sites/default/files/managed/48/88/329298-002.pdf, Oct. 2014, pp. 1-186.
[cited by applicant]
Intel Corporation, “Intel Trust Domain Extensions”, last accessed Aug. 19, 2024, available at: https://www.intel.com/content/www/us/en/developer/articles/technical/intel-trust-domain-extensions.html, pp. 1-7.
[cited by applicant]
International Organization for Standardization and International Electrotechnical Commission, “Information technology—Trusted platform module library”, Technical Report ISO/IEC 11889-1:2015, available at: https://www.is…
[cited by applicant]
Irazoqui, G., et al., “S$A: A Shared Cache Attack That Works Across Cores and Defies VM Sandboxing—and Its Application to AES”, In Proceedings of the 2015 IEEE Symposium on Security and Privacy (SP 2015), San Jose, CA, …
[cited by applicant]
Jain, S., et al. “Application-Level Isolation and Recovery with Solitude”, In Proceedings of the 3rd ACM SIGOPS/EuroSys European Conference on Computer Systems (EuroSys '08), Glasgow, Scotland, UK, Apr. 1-4, 2008, pp. 9…
[cited by applicant]
Jones, R., “Netperf”, last accessed Aug. 19, 2024, available at: https://github.com/HewlettPackard/netperf, pp. 1-4.
[cited by applicant]
Kamp, p. H. and Watson, R.N.M., “Jails: Confining the Omnipotent Root”, In Proceedings of the 2nd International SANE Conference, Maastricht, NL, May 22-25, 2000, pp. 1-15.
[cited by applicant]
Kata Containers Community, “Kata Containers”, last accessed Aug. 19, 2024, available at: https://katacontainers.io/, pp. 1-4.
[cited by applicant]
Klein, G., et al., “seL4: Formal Verification of an OS Kernel”, In Proceedings of the 22nd ACM Symposium on Operating Systems Principles, Big Sky, MT, US, Oct. 11-14, 2009, pp. 207-220.
[cited by applicant]
KVM Contributors, “Tuning KVM”, KVM, last accessed Aug. 20, 2024, available at: https://www.linux-kvm.org/page/Tuning_KVM, pp. 1-2.
[cited by applicant]
Kwon, Y., et al., Sego: Pervasive trusted metadata for efficiently verified untrusted system services. In Proceedings of the Twenty-First International Conference on Architectural Support for Programming Languages and O…
[cited by applicant]
Lampson, B., “Accountability and Freedom”, Sep. 26, 2005, available at: http://research.microsoft.com/en-us/um/people/blampson/Slides/AccountabilityAndFreedomAbstract.htm, pp. 1-26.
[cited by applicant]
Landau, S., “Making Sense from Snowden: What's Significant in the NSA Surveillance Revelations”, In IEEE Security & Privacy, vol. 11, No. 4, Jul.-Aug. 2013, pp. 54-63.
[cited by applicant]
Let's Encrypt, “Let's encrypt stats—let's encrypt”, last accessed Aug. 19, 2024, available at: https://letsencrypt.org/stats/, pp. 1-2.
[cited by applicant]
Li, S.W., et al., “Protecting Cloud Virtual Machines from Hypervisor and Host Operating System Exploits”, In Proceedings of the 28th USENIX Security Symposium, Santa Clara, CA, US, Aug. 14-16, 2019, pp. 1-19.
[cited by applicant]
Li, X., et al., “Design and Verification of the Arm Confidential Compute Architecture”, In Proceedings of 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI 22), Carlsbad, CA, US, Jul. 11-13, 202…
[cited by applicant]
Liang, Z., “Isolated Program Execution: An Application Transparent Approach for Executing Untrusted Programs”, In Proceedings of the 19th Annual Computer Security Applications Conference, Las Vegas, NV, US, Dec. 8-12, 2…
[cited by applicant]
Linux Container Hardening Project, “Linux Container Hardening”, last accessed Aug. 19, 2024, available at: https://containerhardening.org/, pp. 1-5.
[cited by applicant]
Liu, F., et al., “Last-Level Cache Side-Channel Attacks Are Practical”, In Proceedings of the 2015 IEEE Symposium on Security and Privacy (SP 2015), San Jose, CA, US, May 17-21, 2015, pp. 605-622.
[cited by applicant]
Loscocco, P. and Smalley, S., “Integrating Flexible Support for Security Policies into the Linux Operating System”, In Proceedings of the FREENIX Track: 2001 USENIX Annual Technical Conference, Boston, MA, USA, Jun. 25-…
[cited by applicant]
LTP Developers, “LTP—Linux Test Project”, last accessed Aug. 19, 2024, available at: https://linux-test-project.github.io/, pp. 1-3.
[cited by applicant]
Lu, S., et al., “Sequential Aggregate Signatures and Multisignatures without Random Oracles”, In Advances in Cryptology—EUROCRYPT 2006, Lecture Notes in Computer Science, vol. 4004, St. Perersburg, RU, May 28-Jun. 1, 20…
[cited by applicant]
Madhavapeddy, A., et al., “Unikernels: Library operating systems for the cloud”, In ACM SIGARCH Computer Architecture News, vol. 41, No. 1, Mar. 2013, pp. 461-472.
[cited by applicant]
McCune, J.M., et al., “TrustVisor: Efficient TCB Reduction and Attestation”, In Proceedings of the IEEE Symposium on Security and Privacy, Oakland, CA, US, May 16-19, 2010, pp. 143-158.
[cited by applicant]
McVoy, L. and Staelin, C., “Imbench: Portable tools for performance analysis”, In USENIX 1996 Annual Technical Conference (USENIX ATC 1996), San Diego, CA, US, Jan. 1996, pp. 279-294.
[cited by applicant]
MongoDB, Inc., “Mongodb”, last accessed Aug. 19, 2024, available at: https://www.mongodb.com, pp. 1-13.
[cited by applicant]
Nginx, Inc., “Nginx”, last accessed Aug. 19, 2024, available at: https://www.nginx.com/, pp. 1-4.
[cited by applicant]
Office Action dated Nov. 9, 2012 in U.S. Appl. No. 13/104,246, pp. 1-25.
[cited by applicant]
Oracle Corporation, “Mysql”, last accessed Aug. 19, 2024, available at: https://www.mysql.com, pp. 1-3.
[cited by applicant]
Osman, S. et al., “The Design and Implementation of ZAP: A System for Migrating Computing Environments”, In Proceedings of the 5th Symposium on Operating Systems Design and Implementation, Boston, MA, US, Dec. 2002, pp.…
[cited by applicant]
Pfaff, B., et al., “Virtualization Aware File Systems: Getting Beyond the Limitations of Virtual Disks”, In Proceedings of the 3rd Symposium on Networked Systems Design & Implementation (NSDI '06), May 8-10, 2006, pp. 3…
[cited by applicant]
Porter, T. and Duff, T., “Compositing Digital Images”, In ACM SIGGARCH Computer Graphics, vol. 18, No. 3, Jul. 1984, pp. 253-259.
[cited by applicant]
Price, D. and Tucker, A., “Solaris Zones: Operating System Support for Consolidating Commercial Workloads”, In Proceedings of the 18th Large Installation System Administration Conference (LISA '04), Atlanta, GA, US, Nov…
[cited by applicant]
Priebe, C., et al., “SGX-LKL: Securing the host os interface for trusted execution”, In ArXiv, abs/1908.11143, Aug. 2019, pp. 1-17.
[cited by applicant]
Provos, N., “Improving Host Security with System Call Policies”, In Proceedings of the 12th USENIX Security Symposium (SSYM '03), Washington, DC, US, Aug. 4-8, 2003, pp. 257-272.
[cited by applicant]
Redhat, “Podman: The next gernation of linux container tools”, last accessed Aug. 19, 2024, available at: https://podman.io/, pp. 1-8.
[cited by applicant]
Redis Labs, “memtier_benchmark”, last accessed Aug. 19, 2024, available at: https://github.com/RedisLabs/memtier_benchmark, pp. 1-9.
[cited by applicant]
Redis Labs, “Redis Libraries and Tools”, last accessed Aug. 19, 2024, available at: https://redis.io/tools, pp. 1-6.
[cited by applicant]
Redis Labs, “Redis”, last accessed Aug. 19, 2024, available at: https://redis.io/, pp. 1-8.
[cited by applicant]
Reis, C. and Gribble, S.D., “Isolating Web Programs in Modern Browser Architectures”, In Proceedings of the 4th ACM European Conference on Computer Systems (EuroSys '09), Nuremberg, DE, Apr. 1-3, 2009, pp. 219-232.
[cited by applicant]
Ristenpart, T., et al., “Hey, You, Get off of My Cloud: Exploring Information Leakage in Third-party Compute Clouds”, In Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS 2009), Chicago…
[cited by applicant]
Roemer, R., et al., “Return-Oriented Programming: Systems, languages, and applications”, In ACM Transactions on Information and System Security, vol. 15, No. 1, Mar. 2012, pp. 1-42.
[cited by applicant]
Russell. R., “Hackbench”, last accessed Jan. 19, 2008, available at: http://people.redhat.com/mingo/cfs-scheduler/tools/hackbench.c, pp. 1-3.
[cited by applicant]
Sadeghi, A.R., et al., “Security and Privacy Challenges in Industrial Internet of Things”, In Proceedings of the 52nd Annual Design Automation Conference, San Francisco, CA, US, Jun. 7-11, 2015, pp. 1-6.
[cited by applicant]
Saltzer, J.H., et al., “End-to-end Arguments in System Design”, In ACM Transactions on Computer Systems (TOCS), vol. 2, No. 4, Nov. 1984, pp. 277-288.
[cited by applicant]
Samsung Electronics Co., Ltd., “Samsung Knox—White Paper”, last accessed Aug. 19, 2024, available at: https://docs.samsungknox.com/admin/whitepaper/kpe/samsung-knox.htm, pp. 1-8.
[cited by applicant]
Shacham, H., “The Geometry of Innocent Flesh on the Bone: Return-into-Libc Without Function Calls (On the x86)”, Proceedings of the 14th ACM Conference on Computer and Communications Security (CCS '07), Alexandria, VA, …
[cited by applicant]
Shen, Y., et al., “Occlum: Secure and efficient multitasking inside a single enclave of intel sgx”, In Proceedings of the Twenty-Fifth International Conference on Architectural Support for Programming Languages and Oper…
[cited by applicant]
Shen, Z., et al., “X-containers: Breaking down barriers to improve performance and isolation of cloud-native containers”, In Proceedings of the Twenty-Fourth International Conference on Architectural Support for Program…
[cited by applicant]
Soares, L. and Stumm, M., “FlexSC: Flexible System Call Scheduling with Exception-Less System Calls”, In 9th USENIX Symposium on Operating Systems Design and Implementation (OSDI 10), Vancouver, BC, CA, Oct. 4-6, 2010, …
[cited by applicant]
Soltesz, S., et al., “Container-Based Operating System Virtualization: A Scalable, High Performance Alternative to Hypervisors”, In Proceedings of the 2007 EuroSys Conference (EuroSys '07), Lisbon, PT, Mar. 21-23, 2007,…
[cited by applicant]
Steinberg, U. and Kauer, B., “NOVA: A Microhypervisor-based Secure Virtualization Architecture”, In Proceedings of the 5th European Conference on Computer Systems (EuroSys 2010), Paris, FR, Apr. 2010, pp. 209-222.
[cited by applicant]
Stewin, P. and Bystrov, I., “Understanding DMA Malware”, In Proceedings of the 9th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA 2012), , Heraklion, Crete, GR, Jul.…
[cited by applicant]
Sun Microsystems, Inc., “Solaris ZFS Administration Guide”, Jan. 2010, available at: http://docs.oracle.com/cd/E19082-01/817-2271/817-2271.pdf, pp. 1-318.
[cited by applicant]
Suse, “Performance Implications of Cache Modes”, Jul. 30, 2021, available at: https://documentation.suse.com/sles/11-SP4/html/SLES-all/cha-qemu-cachemodes.html, pp. 1-5.
[cited by applicant]
The Apache Software Foundation, “ab—Apache HTTP server benchmarking tool”, last accessed Aug. 19, 2024, available at: http://httpd.apache. org/docs/2.4/programs/ab.html, pp. 1-4.
[cited by applicant]
The Kubernetes Authors, “Persistent Volumes”, last modified Jul. 26, 2024, available at: https://kubernetes.io/docs/concepts/storage/persistent-volumes/, pp. 1-22.
[cited by applicant]
The Kubernetes Authors, “Working with Pods”, last modified Jul. 29, 2024, available at: https://kubernetes.io/docs/concepts/workloads/pods/#working-with-pods, pp. 1-7.
[cited by applicant]
Trusted Firmware Community, “Trusted Firmware—A”, last accessed Aug. 19, 2024, available at: https://developer.arm.com/Tools%20and%20Software/Trusted%20Firmware-A, pp. 1-3.
[cited by applicant]
Tsai, C.C., et al., “Graphene—SGX: A practical library OS for unmodified applications on SGX”, In Proceedings of the 2017 USENIX Annual Technical Conference (USENIX ATC 2017), Santa Clara, CA, US, Jul. 12-14, 2017, pp. …
[cited by applicant]
U.S. Appl. No. 13/104,246, filed May 10, 2011, pp. 1-20.
[cited by applicant]
U.S. Appl. No. 61/333,518, filed May 11, 2010, pp. 1-19.
[cited by applicant]
U.S. Appl. No. 63/190,539, filed May 19, 2021, pp. 1-19.
[cited by applicant]
U.S. Appl. No. 63/553,979, filed Feb. 15, 2024, pp. 1-23.
[cited by applicant]
Van't Hof, A. and Nieh, J., “BlackBox: A Container Security Monitor for Protecting Containers on Untrusted Operating Systems”, In Proceedings of the 16th USENIX Symposium on Operating Systems Design and Implementation (…
[cited by applicant]
VMware Inc., “VMware Workstation 6.5 Release Notes”, Oct. 15, 2008, available at: http://www.wmvare.com/support/ws65/doc/releasenotes_ws65.html, pp. 1-5.
[cited by applicant]
Wagner, D.A., “Janus: An Approach for Confinement of Untrusted Applications”, Master's Thesis, University of California, Aug. 1999, pp. 1-65.
[cited by applicant]
Whitaker, A et al., “Scale and Performance in the Denali Isolation Kernel”, In Proceedings of the Fifth Symposium on Operating Systems Design and Implementation (OSDI '02), Boston, MA, US, Dec. 9-11, 2002, pp. 195-209.
[cited by applicant]
White Paper, “AMD SEV-SNP: Stengthening VM Isolation with Integrity Protection and More”, Solutions Brief, Jan. 2020, pp. 1-20.
[cited by applicant]
Wright, C., et al., “Versatility and Unix Semantics in a Fan-Out Unification File System”, Technical Report FSL-04-01b, Stony Brook University, Jan. 2004, pp. 1-14.
[cited by applicant]
Yang, J. and Shin, K.G., “Using Hypervisor to Provide Data Secrecy for User Applications on a Per-page Basis”, In Proc. of the 4th ACM SIGPLAN/SIGOPS Intl. Conf. on Virtual Execution Environments, Seattle, WA, US, Mar. …
[cited by applicant]
Zhang, Y., et al., “Cross-Tenant Side-Channel Attacks in Paas Clouds”, In Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security (CCS 2014), Nov. 2014, pp. 990-1003.
[cited by applicant]
Zhang, Y., et al., “Cross-VM Side Channels and Their Use to Extract Private Keys”, In Proceedings of the 2012 ACM Conference on Computer and Communications Security (CCS 2012), Raleigh, NC, US, Oct. 16-18, 2012, pp. 1-7…
[cited by applicant]
Zhang, Y., et al., “Shelter: Extending ARM CCA with Isolation in User Space”, In Proceedings of the 32nd USENIX Secutity Symposium, Anaheim, CA, US, Aug. 9-11, 2023, pp. 1-19.
[cited by applicant]
Zinzindohoué, J. K., et al., “Hacl*: A verified modern cryptographic library”, In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (CCS 2017), Dallas, TX, US, Oct. 20-Nov. 3, 2017, p…
[cited by applicant]