4 papers
EBCC: Enclave-Backed Confidential Containers via OCI-Compatible Runtime Integration
Di Lu, Qingwen Zhang, Yujia Liu +4
Container runtimes provide a stable operational interface for deploying, monitoring, and controlling modern workloads, while trusted execution environments (TEEs) provide hardware-…
When Convenience Becomes Risk: A Semantic View of Under-Specification in Host-Acting Agents
Di Lu, Yongzhi Liao, Xutong Mu +5
Host-acting agents promise a convenient interaction model in which users specify goals and the system determines how to realize them. We argue that this convenience introduces a di…
Arca: A Lightweight Confidential Container Architecture for Cloud-Native Environments
Di Lu, Mengna Sun, Qingwen Zhang +5
Confidential containers protect cloud-native workloads using trusted execution environments (TEEs). However, existing Container-in-TEE designs (e.g., Confidential Containers (CoCo)…
DITING: A Static Analyzer for Identifying Bad Partitioning Issues in TEE Applications
Chengyan Ma, Ruidong Han, Jieke Shi +7
Trusted Execution Environment (TEE) enhances the security of mobile applications and cloud services by isolating sensitive code in the secure world from the non-secure normal world…