Vsock-net: Making Paravirtualized Network I/Os for Linux-based Confidential VMs Safe and Fast
Advised by Prof. Shih-Wei Li
Removed the large, attack-surface-heavy Linux network stack from confidential VMs’ Trusted Computing Base (TCB) by delegating network traffic to the host stack. Despite the performance overhead typically introduced by delegation, optimized virtio-vsock communication and leveraged eBPF sockmaps for zero-copy packet redirection in the host kernel, achieving 12.59× higher throughput and up to 10× faster Nginx performance under TLS encryption.
