Conference item
Towards efficient end-to-end encryption for container checkpointing systems
- Abstract:
- Container checkpointing has emerged as a new paradigm for task migration, preemptive scheduling and elastic scaling of microservices. However, as soon as a snapshot that contains raw memory is exposed through the network or shared storage, sensitive data such as keys and passwords may become compromised. Existing solutions rely on encryption to protect data included in snapshots but by doing so prevent important performance optimizations such as memory de-duplication and incremental checkpointing. To address these challenges, we design and implement CRIUsec, an efficient end-to-end encryption scheme for container checkpointing systems built on the open-source CRIU (Checkpoint/Restore In Userspace). Our preliminary evaluation shows that CRIUsec integrates seamlessly with popular container platforms (Docker, Podman, Kubernetes), and compared to existing solutions, achieves an average of 1.57× speedup for memory-intensive workloads, and can be up to 100× faster for compute-intensive workloads.
- Publication status:
- Published
- Peer review status:
- Peer reviewed
Actions
Access Document
- Files:
-
-
(Preview, Version of record, pdf, 985.4KB, Terms of use)
-
- Publisher copy:
- 10.1145/3678015.3680477
Authors
+ Engineering and Physical Sciences Research Council
More from this funder
- Funder identifier:
- https://ror.org/0439y7842
- Grant:
- 2595601
- Publisher:
- Association for Computing Machinery
- Host title:
- Proceedings of the 15th ACM SIGOPS Asia-Pacific Workshop on Systems (APSys 2024)
- Pages:
- 60 - 66
- Publication date:
- 2024-07-18
- Acceptance date:
- 2024-07-01
- Event title:
- 15th ACM SIGOPS Asia-Pacific Workshop on Systems (APSys 2024)
- Event location:
- Kyoto, Japan
- Event website:
- https://ap-sys.org/
- Event start date:
- 2024-09-04
- Event end date:
- 2024-09-05
- DOI:
- ISBN:
- 979-8-4007-1105-3
- Language:
-
English
- Keywords:
- Pubs id:
-
2016675
- Local pid:
-
pubs:2016675
- Deposit date:
-
2024-07-18
Terms of use
- Copyright holder:
- Stoyanov et al.
- Copyright date:
- 2024
- Rights statement:
- © 2024 Copyright held by the owner/author(s). Publication rights licensed to ACM.
- Notes:
- This paper was presented at the 15th ACM SIGOPS Asia-Pacific Workshop on Systems (APSys 2024), 4th-5th September 2024, Kyoto, Japan.
- Licence:
- CC Attribution (CC BY)
If you are the owner of this record, you can report an update to it here: Report update to this record