Conference item icon

Conference item

Towards efficient end-to-end encryption for container checkpointing systems

Abstract:
Container checkpointing has emerged as a new paradigm for task migration, preemptive scheduling and elastic scaling of microservices. However, as soon as a snapshot that contains raw memory is exposed through the network or shared storage, sensitive data such as keys and passwords may become compromised. Existing solutions rely on encryption to protect data included in snapshots but by doing so prevent important performance optimizations such as memory de-duplication and incremental checkpointing. To address these challenges, we design and implement CRIUsec, an efficient end-to-end encryption scheme for container checkpointing systems built on the open-source CRIU (Checkpoint/Restore In Userspace). Our preliminary evaluation shows that CRIUsec integrates seamlessly with popular container platforms (Docker, Podman, Kubernetes), and compared to existing solutions, achieves an average of 1.57× speedup for memory-intensive workloads, and can be up to 100× faster for compute-intensive workloads.
Publication status:
Published
Peer review status:
Peer reviewed

Actions


Access Document


Publisher copy:
10.1145/3678015.3680477

Authors


More by this author
Institution:
University of Oxford
Division:
MPLS
Department:
Engineering Science
Oxford college:
Somerville College
Role:
Author
ORCID:
0000-0001-9688-2615


More from this funder
Funder identifier:
https://ror.org/0439y7842
Grant:
2595601


Publisher:
Association for Computing Machinery
Host title:
Proceedings of the 15th ACM SIGOPS Asia-Pacific Workshop on Systems (APSys 2024)
Pages:
60 - 66
Publication date:
2024-07-18
Acceptance date:
2024-07-01
Event title:
15th ACM SIGOPS Asia-Pacific Workshop on Systems (APSys 2024)
Event location:
Kyoto, Japan
Event website:
https://ap-sys.org/
Event start date:
2024-09-04
Event end date:
2024-09-05
DOI:
ISBN:
979-8-4007-1105-3


Language:
English
Keywords:
Pubs id:
2016675
Local pid:
pubs:2016675
Deposit date:
2024-07-18

Terms of use



Views and Downloads






If you are the owner of this record, you can report an update to it here: Report update to this record

TO TOP