Repository files navigation

SecureExecutor

$SecureExecutor$ is a utility that automatically builds and runs SCONE containers.

These containers wrap C++/Python/Rust applications and are designed to run within SGX enclaves to leverage Trusted Execution Environment (TEE) functionality.

The ultimate goal of $SecureExecutor$ is to automate the process of running applications in enclaves. To achieve this, the utility was initially designed to collect minimal computational units, known as lambda functions, to build trusted images capable of leveraging TEEs. Following this, research activities are conducted to extend this functionality to a broader range of existing applications.

For this tool, the Community/Evaluation edition of SCONE is used, providing services that run inside enclaves in prerelease mode. For this reason, before using the tool, first create an account and login in its registry.

Usage

$SecureExecutor$ can take a large number of different input parameters. Just to name a few of them:

Usage: ./SecureExecutor [Option]... [Option]... Usage: ./SecureExecutor --lambda --function-name hello [--cpp/--rust/--python] [--new/--build/--run/--clean] Usage: ./SecureExecutor --app --path Dockerfiles/apps/steganography.Dockerfile [--build/--run] Usage: ./SecureExecutor --edgeless-node [--build/--run] Usage: ./SecureExecutor --edgeless-function --function-name hello [--rust/--python] [--new/--build] Options: -b, --build Use this flag to build the target image from the given function -c, --clean Clean the generated image (this requires to give the functionfunction name you want to clean) -d, --dynamic In case you want to dynamically link your executable use this flag (only for--lambdain --cpp, this produces smaller in size images TBI) -e, --env-var var You can use this, to pass multiple ENV vars during 'docker run ..' -f, --function-name functionSelect the name of the functionyou want to build or run (requires --lambda/--edgeless-function) -g, --tag tag_name If you want to provide an optional tag for your image, do it using this flag -h, --help Print this help menu and exit -n, --new Use this flag if you want to create a new lambda function -p, --path Use this flag to specify the path to the Dockerfile you want to use (requires --app) -r, --run Pass this flag to run a container -s, --static In case you want to statically link your executable use this flag (only for--lambdain --cpp, this produces larger in size images, default operation) -v, --volume absolute_path If you want to bind mound a directory use this option (MUST provide an absolute path) --lambda Use this to build a lambda function --app Use this to build from a Dockerfile --edgeless-node Use the edgeless node as target --edgeless-function Use this to build an edgeless-function --cpp Use a cpp functionas target (requires --lambda) --python Use a python functionas target (requires --lambda/--edgeless-function) --rust Use a rust functionas target (requires --lambda/--edgeless-function) 

Project Tree Explanation

.
├── doc # Extra documentation files for the repository
├── Dockerfiles # Dockerfiles for base images, applications, and lambda functions
├── LAS # Initial scripts for Local Attestation
├── scripts # Auxiliary scripts to simplify tasks
├── src # Source code for SecureExecutor
├── sysinfo # Modified Sysinfo Rust crate code (see sysinfo problem related to EDGELESS)
├── sysinfo_untrusted # Untrusted portion of sysinfo sources
├── templates # Templates for creating target lambda functions
├── test# Test scripts
├── SecureExecutor # Core of SecureExecutor (main function)
└── README.md # This documentation file

Lambdas

To understand how to create and run a lambda function, please read this file.

Applications

For more information regarding the applications that $SecureExecutor$ has been tested on so far, please refer to this file.

Demos

  • EDGELESS: This demo video showcases the creation of the trusted binary for the EDGELESS node using $SecureExecutor$, followed by the execution of a function on the node within the EDGELESS platform.

Dependencies

  • A Linux based machine with Intel SGX capabilities (developed/tested on a NUC device that runs Ubuntu 22.04). Read this if you want to know how to setup a system that is ready to run this tool.

  • Docker

curl -fsSL https://get.docker.com -o get-docker.sh
sudo sh get-docker.sh
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh

Known issues

  • Attestation: To ensure end-to-end secure execution, the appropriate attestation mechanisms have yet to be integrated into the current system.

    See SCONE CAS, LAS and Initial LAS experiments in this repository.

  • Encryption during transfer: To ensure end-to-end secure execution, encryption should also be enabled during the transmission of data from the client to the enclave.

  • Evaluate the system while running different workflows that contain diverse functions. Read EDGELESS examples tested section to gain more information.

Publication

Zenodo | IEEE Xplore

The following publication: "SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security" explains the high-level purpose of this tool and provides additional information about its internal behavior. Hence, it serves as a good starting point for understanding the tool’s internals. A pre-print version, is also available here.

Tests

This repository also includes an automated unit test mechanism. In the test/ directory, the run_tests.sh file is available to execute all tests.

./test/run_tests.sh

Test files exist in the respective folders in the test/ directory. If you want to run only for a specific case tests, then pass as an input argument the relative path.

# Syntax: ./test/run_tests.sh <file1_path> <file2_path> ...
./test/run_tests.sh ./test/lambdas/cpp.sh

Cite

If you would like to cite this work in another publication, please use the following citation.

Zenodo

[1]C. Spyridakis, A. Aktypi, T. Kyriakakisand S. Ioannidis, “SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security”, Oct. 2024. doi: 10.5281/zenodo.13986642.

IEEE Xplore

@INPROCEEDINGS{10679349,
author={Spyridakis, Christos and Aktypi, Angeliki and Kyriakakis, Thomas and Ioannidis, Sotiris},
booktitle={2024 IEEE International Conference on Cyber Security and Resilience (CSR)}, title={SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security}, year={2024},
volume={},
number={},
pages={827-832},
keywords={Linux;Containers;Software;Silicon;Libraries;Complexity theory;Security;Security;TEE;Intel SGX;SCONE},
doi={10.1109/CSR61664.2024.10679349}}

Funding & Support

This project has received funding from the European Health and Digital Executive Agency (HADEA) program under Grant Agreement No 101092950 (EDGELESS project) and support from the SCONTAIN team.

About

SecureExecutor is a tool to run code inside SGX enclaves

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

SecureExecutor

$SecureExecutor$ is a utility that automatically builds and runs SCONE containers.

These containers wrap C++/Python/Rust applications and are designed to run within SGX enclaves to leverage Trusted Execution Environment (TEE) functionality.

The ultimate goal of $SecureExecutor$ is to automate the process of running applications in enclaves. To achieve this, the utility was initially designed to collect minimal computational units, known as lambda functions, to build trusted images capable of leveraging TEEs. Following this, research activities are conducted to extend this functionality to a broader range of existing applications.

For this tool, the Community/Evaluation edition of SCONE is used, providing services that run inside enclaves in prerelease mode. For this reason, before using the tool, first create an account and login in its registry.

Usage

$SecureExecutor$ can take a large number of different input parameters. Just to name a few of them:

Usage: ./SecureExecutor [Option]... [Option]... Usage: ./SecureExecutor --lambda --function-name hello [--cpp/--rust/--python] [--new/--build/--run/--clean] Usage: ./SecureExecutor --app --path Dockerfiles/apps/steganography.Dockerfile [--build/--run] Usage: ./SecureExecutor --edgeless-node [--build/--run] Usage: ./SecureExecutor --edgeless-function --function-name hello [--rust/--python] [--new/--build] Options: -b, --build Use this flag to build the target image from the given function -c, --clean Clean the generated image (this requires to give the functionfunction name you want to clean) -d, --dynamic In case you want to dynamically link your executable use this flag (only for--lambdain --cpp, this produces smaller in size images TBI) -e, --env-var var You can use this, to pass multiple ENV vars during 'docker run ..' -f, --function-name functionSelect the name of the functionyou want to build or run (requires --lambda/--edgeless-function) -g, --tag tag_name If you want to provide an optional tag for your image, do it using this flag -h, --help Print this help menu and exit -n, --new Use this flag if you want to create a new lambda function -p, --path Use this flag to specify the path to the Dockerfile you want to use (requires --app) -r, --run Pass this flag to run a container -s, --static In case you want to statically link your executable use this flag (only for--lambdain --cpp, this produces larger in size images, default operation) -v, --volume absolute_path If you want to bind mound a directory use this option (MUST provide an absolute path) --lambda Use this to build a lambda function --app Use this to build from a Dockerfile --edgeless-node Use the edgeless node as target --edgeless-function Use this to build an edgeless-function --cpp Use a cpp functionas target (requires --lambda) --python Use a python functionas target (requires --lambda/--edgeless-function) --rust Use a rust functionas target (requires --lambda/--edgeless-function) 

Project Tree Explanation

.
├── doc # Extra documentation files for the repository
├── Dockerfiles # Dockerfiles for base images, applications, and lambda functions
├── LAS # Initial scripts for Local Attestation
├── scripts # Auxiliary scripts to simplify tasks
├── src # Source code for SecureExecutor
├── sysinfo # Modified Sysinfo Rust crate code (see sysinfo problem related to EDGELESS)
├── sysinfo_untrusted # Untrusted portion of sysinfo sources
├── templates # Templates for creating target lambda functions
├── test# Test scripts
├── SecureExecutor # Core of SecureExecutor (main function)
└── README.md # This documentation file

Lambdas

To understand how to create and run a lambda function, please read this file.

Applications

For more information regarding the applications that $SecureExecutor$ has been tested on so far, please refer to this file.

Demos

  • EDGELESS: This demo video showcases the creation of the trusted binary for the EDGELESS node using $SecureExecutor$, followed by the execution of a function on the node within the EDGELESS platform.

Dependencies

  • A Linux based machine with Intel SGX capabilities (developed/tested on a NUC device that runs Ubuntu 22.04). Read this if you want to know how to setup a system that is ready to run this tool.

  • Docker

curl -fsSL https://get.docker.com -o get-docker.sh
sudo sh get-docker.sh
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh

Known issues

  • Attestation: To ensure end-to-end secure execution, the appropriate attestation mechanisms have yet to be integrated into the current system.

    See SCONE CAS, LAS and Initial LAS experiments in this repository.

  • Encryption during transfer: To ensure end-to-end secure execution, encryption should also be enabled during the transmission of data from the client to the enclave.

  • Evaluate the system while running different workflows that contain diverse functions. Read EDGELESS examples tested section to gain more information.

Publication

Zenodo | IEEE Xplore

The following publication: "SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security" explains the high-level purpose of this tool and provides additional information about its internal behavior. Hence, it serves as a good starting point for understanding the tool’s internals. A pre-print version, is also available here.

Tests

This repository also includes an automated unit test mechanism. In the test/ directory, the run_tests.sh file is available to execute all tests.

./test/run_tests.sh

Test files exist in the respective folders in the test/ directory. If you want to run only for a specific case tests, then pass as an input argument the relative path.

# Syntax: ./test/run_tests.sh <file1_path> <file2_path> ...
./test/run_tests.sh ./test/lambdas/cpp.sh

Cite

If you would like to cite this work in another publication, please use the following citation.

Zenodo

[1]C. Spyridakis, A. Aktypi, T. Kyriakakisand S. Ioannidis, “SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security”, Oct. 2024. doi: 10.5281/zenodo.13986642.

IEEE Xplore

@INPROCEEDINGS{10679349,
author={Spyridakis, Christos and Aktypi, Angeliki and Kyriakakis, Thomas and Ioannidis, Sotiris},
booktitle={2024 IEEE International Conference on Cyber Security and Resilience (CSR)}, title={SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security}, year={2024},
volume={},
number={},
pages={827-832},
keywords={Linux;Containers;Software;Silicon;Libraries;Complexity theory;Security;Security;TEE;Intel SGX;SCONE},
doi={10.1109/CSR61664.2024.10679349}}

Funding & Support

This project has received funding from the European Health and Digital Executive Agency (HADEA) program under Grant Agreement No 101092950 (EDGELESS project) and support from the SCONTAIN team.

About

SecureExecutor is a tool to run code inside SGX enclaves

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

SecureExecutor

$SecureExecutor$ is a utility that automatically builds and runs SCONE containers.

These containers wrap C++/Python/Rust applications and are designed to run within SGX enclaves to leverage Trusted Execution Environment (TEE) functionality.

The ultimate goal of $SecureExecutor$ is to automate the process of running applications in enclaves. To achieve this, the utility was initially designed to collect minimal computational units, known as lambda functions, to build trusted images capable of leveraging TEEs. Following this, research activities are conducted to extend this functionality to a broader range of existing applications.

For this tool, the Community/Evaluation edition of SCONE is used, providing services that run inside enclaves in prerelease mode. For this reason, before using the tool, first create an account and login in its registry.

Usage

$SecureExecutor$ can take a large number of different input parameters. Just to name a few of them:

Usage: ./SecureExecutor [Option]... [Option]... Usage: ./SecureExecutor --lambda --function-name hello [--cpp/--rust/--python] [--new/--build/--run/--clean] Usage: ./SecureExecutor --app --path Dockerfiles/apps/steganography.Dockerfile [--build/--run] Usage: ./SecureExecutor --edgeless-node [--build/--run] Usage: ./SecureExecutor --edgeless-function --function-name hello [--rust/--python] [--new/--build] Options: -b, --build Use this flag to build the target image from the given function -c, --clean Clean the generated image (this requires to give the functionfunction name you want to clean) -d, --dynamic In case you want to dynamically link your executable use this flag (only for--lambdain --cpp, this produces smaller in size images TBI) -e, --env-var var You can use this, to pass multiple ENV vars during 'docker run ..' -f, --function-name functionSelect the name of the functionyou want to build or run (requires --lambda/--edgeless-function) -g, --tag tag_name If you want to provide an optional tag for your image, do it using this flag -h, --help Print this help menu and exit -n, --new Use this flag if you want to create a new lambda function -p, --path Use this flag to specify the path to the Dockerfile you want to use (requires --app) -r, --run Pass this flag to run a container -s, --static In case you want to statically link your executable use this flag (only for--lambdain --cpp, this produces larger in size images, default operation) -v, --volume absolute_path If you want to bind mound a directory use this option (MUST provide an absolute path) --lambda Use this to build a lambda function --app Use this to build from a Dockerfile --edgeless-node Use the edgeless node as target --edgeless-function Use this to build an edgeless-function --cpp Use a cpp functionas target (requires --lambda) --python Use a python functionas target (requires --lambda/--edgeless-function) --rust Use a rust functionas target (requires --lambda/--edgeless-function) 

Project Tree Explanation

.
├── doc # Extra documentation files for the repository
├── Dockerfiles # Dockerfiles for base images, applications, and lambda functions
├── LAS # Initial scripts for Local Attestation
├── scripts # Auxiliary scripts to simplify tasks
├── src # Source code for SecureExecutor
├── sysinfo # Modified Sysinfo Rust crate code (see sysinfo problem related to EDGELESS)
├── sysinfo_untrusted # Untrusted portion of sysinfo sources
├── templates # Templates for creating target lambda functions
├── test# Test scripts
├── SecureExecutor # Core of SecureExecutor (main function)
└── README.md # This documentation file

Lambdas

To understand how to create and run a lambda function, please read this file.

Applications

For more information regarding the applications that $SecureExecutor$ has been tested on so far, please refer to this file.

Demos

  • EDGELESS: This demo video showcases the creation of the trusted binary for the EDGELESS node using $SecureExecutor$, followed by the execution of a function on the node within the EDGELESS platform.

Dependencies

  • A Linux based machine with Intel SGX capabilities (developed/tested on a NUC device that runs Ubuntu 22.04). Read this if you want to know how to setup a system that is ready to run this tool.

  • Docker

curl -fsSL https://get.docker.com -o get-docker.sh
sudo sh get-docker.sh
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh

Known issues

  • Attestation: To ensure end-to-end secure execution, the appropriate attestation mechanisms have yet to be integrated into the current system.

    See SCONE CAS, LAS and Initial LAS experiments in this repository.

  • Encryption during transfer: To ensure end-to-end secure execution, encryption should also be enabled during the transmission of data from the client to the enclave.

  • Evaluate the system while running different workflows that contain diverse functions. Read EDGELESS examples tested section to gain more information.

Publication

Zenodo | IEEE Xplore

The following publication: "SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security" explains the high-level purpose of this tool and provides additional information about its internal behavior. Hence, it serves as a good starting point for understanding the tool’s internals. A pre-print version, is also available here.

Tests

This repository also includes an automated unit test mechanism. In the test/ directory, the run_tests.sh file is available to execute all tests.

./test/run_tests.sh

Test files exist in the respective folders in the test/ directory. If you want to run only for a specific case tests, then pass as an input argument the relative path.

# Syntax: ./test/run_tests.sh <file1_path> <file2_path> ...
./test/run_tests.sh ./test/lambdas/cpp.sh

Cite

If you would like to cite this work in another publication, please use the following citation.

Zenodo

[1]C. Spyridakis, A. Aktypi, T. Kyriakakisand S. Ioannidis, “SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security”, Oct. 2024. doi: 10.5281/zenodo.13986642.

IEEE Xplore

@INPROCEEDINGS{10679349,
author={Spyridakis, Christos and Aktypi, Angeliki and Kyriakakis, Thomas and Ioannidis, Sotiris},
booktitle={2024 IEEE International Conference on Cyber Security and Resilience (CSR)}, title={SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security}, year={2024},
volume={},
number={},
pages={827-832},
keywords={Linux;Containers;Software;Silicon;Libraries;Complexity theory;Security;Security;TEE;Intel SGX;SCONE},
doi={10.1109/CSR61664.2024.10679349}}

Funding & Support

This project has received funding from the European Health and Digital Executive Agency (HADEA) program under Grant Agreement No 101092950 (EDGELESS project) and support from the SCONTAIN team.

About

SecureExecutor is a tool to run code inside SGX enclaves

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

SecureExecutor

$SecureExecutor$ is a utility that automatically builds and runs SCONE containers.

These containers wrap C++/Python/Rust applications and are designed to run within SGX enclaves to leverage Trusted Execution Environment (TEE) functionality.

The ultimate goal of $SecureExecutor$ is to automate the process of running applications in enclaves. To achieve this, the utility was initially designed to collect minimal computational units, known as lambda functions, to build trusted images capable of leveraging TEEs. Following this, research activities are conducted to extend this functionality to a broader range of existing applications.

For this tool, the Community/Evaluation edition of SCONE is used, providing services that run inside enclaves in prerelease mode. For this reason, before using the tool, first create an account and login in its registry.

Usage

$SecureExecutor$ can take a large number of different input parameters. Just to name a few of them:

Usage: ./SecureExecutor [Option]... [Option]... Usage: ./SecureExecutor --lambda --function-name hello [--cpp/--rust/--python] [--new/--build/--run/--clean] Usage: ./SecureExecutor --app --path Dockerfiles/apps/steganography.Dockerfile [--build/--run] Usage: ./SecureExecutor --edgeless-node [--build/--run] Usage: ./SecureExecutor --edgeless-function --function-name hello [--rust/--python] [--new/--build] Options: -b, --build Use this flag to build the target image from the given function -c, --clean Clean the generated image (this requires to give the functionfunction name you want to clean) -d, --dynamic In case you want to dynamically link your executable use this flag (only for--lambdain --cpp, this produces smaller in size images TBI) -e, --env-var var You can use this, to pass multiple ENV vars during 'docker run ..' -f, --function-name functionSelect the name of the functionyou want to build or run (requires --lambda/--edgeless-function) -g, --tag tag_name If you want to provide an optional tag for your image, do it using this flag -h, --help Print this help menu and exit -n, --new Use this flag if you want to create a new lambda function -p, --path Use this flag to specify the path to the Dockerfile you want to use (requires --app) -r, --run Pass this flag to run a container -s, --static In case you want to statically link your executable use this flag (only for--lambdain --cpp, this produces larger in size images, default operation) -v, --volume absolute_path If you want to bind mound a directory use this option (MUST provide an absolute path) --lambda Use this to build a lambda function --app Use this to build from a Dockerfile --edgeless-node Use the edgeless node as target --edgeless-function Use this to build an edgeless-function --cpp Use a cpp functionas target (requires --lambda) --python Use a python functionas target (requires --lambda/--edgeless-function) --rust Use a rust functionas target (requires --lambda/--edgeless-function) 

Project Tree Explanation

.
├── doc # Extra documentation files for the repository
├── Dockerfiles # Dockerfiles for base images, applications, and lambda functions
├── LAS # Initial scripts for Local Attestation
├── scripts # Auxiliary scripts to simplify tasks
├── src # Source code for SecureExecutor
├── sysinfo # Modified Sysinfo Rust crate code (see sysinfo problem related to EDGELESS)
├── sysinfo_untrusted # Untrusted portion of sysinfo sources
├── templates # Templates for creating target lambda functions
├── test# Test scripts
├── SecureExecutor # Core of SecureExecutor (main function)
└── README.md # This documentation file

Lambdas

To understand how to create and run a lambda function, please read this file.

Applications

For more information regarding the applications that $SecureExecutor$ has been tested on so far, please refer to this file.

Demos

  • EDGELESS: This demo video showcases the creation of the trusted binary for the EDGELESS node using $SecureExecutor$, followed by the execution of a function on the node within the EDGELESS platform.

Dependencies

  • A Linux based machine with Intel SGX capabilities (developed/tested on a NUC device that runs Ubuntu 22.04). Read this if you want to know how to setup a system that is ready to run this tool.

  • Docker

curl -fsSL https://get.docker.com -o get-docker.sh
sudo sh get-docker.sh
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh

Known issues

  • Attestation: To ensure end-to-end secure execution, the appropriate attestation mechanisms have yet to be integrated into the current system.

    See SCONE CAS, LAS and Initial LAS experiments in this repository.

  • Encryption during transfer: To ensure end-to-end secure execution, encryption should also be enabled during the transmission of data from the client to the enclave.

  • Evaluate the system while running different workflows that contain diverse functions. Read EDGELESS examples tested section to gain more information.

Publication

Zenodo | IEEE Xplore

The following publication: "SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security" explains the high-level purpose of this tool and provides additional information about its internal behavior. Hence, it serves as a good starting point for understanding the tool’s internals. A pre-print version, is also available here.

Tests

This repository also includes an automated unit test mechanism. In the test/ directory, the run_tests.sh file is available to execute all tests.

./test/run_tests.sh

Test files exist in the respective folders in the test/ directory. If you want to run only for a specific case tests, then pass as an input argument the relative path.

# Syntax: ./test/run_tests.sh <file1_path> <file2_path> ...
./test/run_tests.sh ./test/lambdas/cpp.sh

Cite

If you would like to cite this work in another publication, please use the following citation.

Zenodo

[1]C. Spyridakis, A. Aktypi, T. Kyriakakisand S. Ioannidis, “SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security”, Oct. 2024. doi: 10.5281/zenodo.13986642.

IEEE Xplore

@INPROCEEDINGS{10679349,
author={Spyridakis, Christos and Aktypi, Angeliki and Kyriakakis, Thomas and Ioannidis, Sotiris},
booktitle={2024 IEEE International Conference on Cyber Security and Resilience (CSR)}, title={SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security}, year={2024},
volume={},
number={},
pages={827-832},
keywords={Linux;Containers;Software;Silicon;Libraries;Complexity theory;Security;Security;TEE;Intel SGX;SCONE},
doi={10.1109/CSR61664.2024.10679349}}

Funding & Support

This project has received funding from the European Health and Digital Executive Agency (HADEA) program under Grant Agreement No 101092950 (EDGELESS project) and support from the SCONTAIN team.

About

SecureExecutor is a tool to run code inside SGX enclaves

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

SecureExecutor

$SecureExecutor$ is a utility that automatically builds and runs SCONE containers.

These containers wrap C++/Python/Rust applications and are designed to run within SGX enclaves to leverage Trusted Execution Environment (TEE) functionality.

The ultimate goal of $SecureExecutor$ is to automate the process of running applications in enclaves. To achieve this, the utility was initially designed to collect minimal computational units, known as lambda functions, to build trusted images capable of leveraging TEEs. Following this, research activities are conducted to extend this functionality to a broader range of existing applications.

For this tool, the Community/Evaluation edition of SCONE is used, providing services that run inside enclaves in prerelease mode. For this reason, before using the tool, first create an account and login in its registry.

Usage

$SecureExecutor$ can take a large number of different input parameters. Just to name a few of them:

Usage: ./SecureExecutor [Option]... [Option]... Usage: ./SecureExecutor --lambda --function-name hello [--cpp/--rust/--python] [--new/--build/--run/--clean] Usage: ./SecureExecutor --app --path Dockerfiles/apps/steganography.Dockerfile [--build/--run] Usage: ./SecureExecutor --edgeless-node [--build/--run] Usage: ./SecureExecutor --edgeless-function --function-name hello [--rust/--python] [--new/--build] Options: -b, --build Use this flag to build the target image from the given function -c, --clean Clean the generated image (this requires to give the functionfunction name you want to clean) -d, --dynamic In case you want to dynamically link your executable use this flag (only for--lambdain --cpp, this produces smaller in size images TBI) -e, --env-var var You can use this, to pass multiple ENV vars during 'docker run ..' -f, --function-name functionSelect the name of the functionyou want to build or run (requires --lambda/--edgeless-function) -g, --tag tag_name If you want to provide an optional tag for your image, do it using this flag -h, --help Print this help menu and exit -n, --new Use this flag if you want to create a new lambda function -p, --path Use this flag to specify the path to the Dockerfile you want to use (requires --app) -r, --run Pass this flag to run a container -s, --static In case you want to statically link your executable use this flag (only for--lambdain --cpp, this produces larger in size images, default operation) -v, --volume absolute_path If you want to bind mound a directory use this option (MUST provide an absolute path) --lambda Use this to build a lambda function --app Use this to build from a Dockerfile --edgeless-node Use the edgeless node as target --edgeless-function Use this to build an edgeless-function --cpp Use a cpp functionas target (requires --lambda) --python Use a python functionas target (requires --lambda/--edgeless-function) --rust Use a rust functionas target (requires --lambda/--edgeless-function) 

Project Tree Explanation

.
├── doc # Extra documentation files for the repository
├── Dockerfiles # Dockerfiles for base images, applications, and lambda functions
├── LAS # Initial scripts for Local Attestation
├── scripts # Auxiliary scripts to simplify tasks
├── src # Source code for SecureExecutor
├── sysinfo # Modified Sysinfo Rust crate code (see sysinfo problem related to EDGELESS)
├── sysinfo_untrusted # Untrusted portion of sysinfo sources
├── templates # Templates for creating target lambda functions
├── test# Test scripts
├── SecureExecutor # Core of SecureExecutor (main function)
└── README.md # This documentation file

Lambdas

To understand how to create and run a lambda function, please read this file.

Applications

For more information regarding the applications that $SecureExecutor$ has been tested on so far, please refer to this file.

Demos

  • EDGELESS: This demo video showcases the creation of the trusted binary for the EDGELESS node using $SecureExecutor$, followed by the execution of a function on the node within the EDGELESS platform.

Dependencies

  • A Linux based machine with Intel SGX capabilities (developed/tested on a NUC device that runs Ubuntu 22.04). Read this if you want to know how to setup a system that is ready to run this tool.

  • Docker

curl -fsSL https://get.docker.com -o get-docker.sh
sudo sh get-docker.sh
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh

Known issues

  • Attestation: To ensure end-to-end secure execution, the appropriate attestation mechanisms have yet to be integrated into the current system.

    See SCONE CAS, LAS and Initial LAS experiments in this repository.

  • Encryption during transfer: To ensure end-to-end secure execution, encryption should also be enabled during the transmission of data from the client to the enclave.

  • Evaluate the system while running different workflows that contain diverse functions. Read EDGELESS examples tested section to gain more information.

Publication

Zenodo | IEEE Xplore

The following publication: "SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security" explains the high-level purpose of this tool and provides additional information about its internal behavior. Hence, it serves as a good starting point for understanding the tool’s internals. A pre-print version, is also available here.

Tests

This repository also includes an automated unit test mechanism. In the test/ directory, the run_tests.sh file is available to execute all tests.

./test/run_tests.sh

Test files exist in the respective folders in the test/ directory. If you want to run only for a specific case tests, then pass as an input argument the relative path.

# Syntax: ./test/run_tests.sh <file1_path> <file2_path> ...
./test/run_tests.sh ./test/lambdas/cpp.sh

Cite

If you would like to cite this work in another publication, please use the following citation.

Zenodo

[1]C. Spyridakis, A. Aktypi, T. Kyriakakisand S. Ioannidis, “SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security”, Oct. 2024. doi: 10.5281/zenodo.13986642.

IEEE Xplore

@INPROCEEDINGS{10679349,
author={Spyridakis, Christos and Aktypi, Angeliki and Kyriakakis, Thomas and Ioannidis, Sotiris},
booktitle={2024 IEEE International Conference on Cyber Security and Resilience (CSR)}, title={SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security}, year={2024},
volume={},
number={},
pages={827-832},
keywords={Linux;Containers;Software;Silicon;Libraries;Complexity theory;Security;Security;TEE;Intel SGX;SCONE},
doi={10.1109/CSR61664.2024.10679349}}

Funding & Support

This project has received funding from the European Health and Digital Executive Agency (HADEA) program under Grant Agreement No 101092950 (EDGELESS project) and support from the SCONTAIN team.

About

SecureExecutor is a tool to run code inside SGX enclaves

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

SecureExecutor

$SecureExecutor$ is a utility that automatically builds and runs SCONE containers.

These containers wrap C++/Python/Rust applications and are designed to run within SGX enclaves to leverage Trusted Execution Environment (TEE) functionality.

The ultimate goal of $SecureExecutor$ is to automate the process of running applications in enclaves. To achieve this, the utility was initially designed to collect minimal computational units, known as lambda functions, to build trusted images capable of leveraging TEEs. Following this, research activities are conducted to extend this functionality to a broader range of existing applications.

For this tool, the Community/Evaluation edition of SCONE is used, providing services that run inside enclaves in prerelease mode. For this reason, before using the tool, first create an account and login in its registry.

Usage

$SecureExecutor$ can take a large number of different input parameters. Just to name a few of them:

Usage: ./SecureExecutor [Option]... [Option]... Usage: ./SecureExecutor --lambda --function-name hello [--cpp/--rust/--python] [--new/--build/--run/--clean] Usage: ./SecureExecutor --app --path Dockerfiles/apps/steganography.Dockerfile [--build/--run] Usage: ./SecureExecutor --edgeless-node [--build/--run] Usage: ./SecureExecutor --edgeless-function --function-name hello [--rust/--python] [--new/--build] Options: -b, --build Use this flag to build the target image from the given function -c, --clean Clean the generated image (this requires to give the functionfunction name you want to clean) -d, --dynamic In case you want to dynamically link your executable use this flag (only for--lambdain --cpp, this produces smaller in size images TBI) -e, --env-var var You can use this, to pass multiple ENV vars during 'docker run ..' -f, --function-name functionSelect the name of the functionyou want to build or run (requires --lambda/--edgeless-function) -g, --tag tag_name If you want to provide an optional tag for your image, do it using this flag -h, --help Print this help menu and exit -n, --new Use this flag if you want to create a new lambda function -p, --path Use this flag to specify the path to the Dockerfile you want to use (requires --app) -r, --run Pass this flag to run a container -s, --static In case you want to statically link your executable use this flag (only for--lambdain --cpp, this produces larger in size images, default operation) -v, --volume absolute_path If you want to bind mound a directory use this option (MUST provide an absolute path) --lambda Use this to build a lambda function --app Use this to build from a Dockerfile --edgeless-node Use the edgeless node as target --edgeless-function Use this to build an edgeless-function --cpp Use a cpp functionas target (requires --lambda) --python Use a python functionas target (requires --lambda/--edgeless-function) --rust Use a rust functionas target (requires --lambda/--edgeless-function) 

Project Tree Explanation

.
├── doc # Extra documentation files for the repository
├── Dockerfiles # Dockerfiles for base images, applications, and lambda functions
├── LAS # Initial scripts for Local Attestation
├── scripts # Auxiliary scripts to simplify tasks
├── src # Source code for SecureExecutor
├── sysinfo # Modified Sysinfo Rust crate code (see sysinfo problem related to EDGELESS)
├── sysinfo_untrusted # Untrusted portion of sysinfo sources
├── templates # Templates for creating target lambda functions
├── test# Test scripts
├── SecureExecutor # Core of SecureExecutor (main function)
└── README.md # This documentation file

Lambdas

To understand how to create and run a lambda function, please read this file.

Applications

For more information regarding the applications that $SecureExecutor$ has been tested on so far, please refer to this file.

Demos

  • EDGELESS: This demo video showcases the creation of the trusted binary for the EDGELESS node using $SecureExecutor$, followed by the execution of a function on the node within the EDGELESS platform.

Dependencies

  • A Linux based machine with Intel SGX capabilities (developed/tested on a NUC device that runs Ubuntu 22.04). Read this if you want to know how to setup a system that is ready to run this tool.

  • Docker

curl -fsSL https://get.docker.com -o get-docker.sh
sudo sh get-docker.sh
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh

Known issues

  • Attestation: To ensure end-to-end secure execution, the appropriate attestation mechanisms have yet to be integrated into the current system.

    See SCONE CAS, LAS and Initial LAS experiments in this repository.

  • Encryption during transfer: To ensure end-to-end secure execution, encryption should also be enabled during the transmission of data from the client to the enclave.

  • Evaluate the system while running different workflows that contain diverse functions. Read EDGELESS examples tested section to gain more information.

Publication

Zenodo | IEEE Xplore

The following publication: "SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security" explains the high-level purpose of this tool and provides additional information about its internal behavior. Hence, it serves as a good starting point for understanding the tool’s internals. A pre-print version, is also available here.

Tests

This repository also includes an automated unit test mechanism. In the test/ directory, the run_tests.sh file is available to execute all tests.

./test/run_tests.sh

Test files exist in the respective folders in the test/ directory. If you want to run only for a specific case tests, then pass as an input argument the relative path.

# Syntax: ./test/run_tests.sh <file1_path> <file2_path> ...
./test/run_tests.sh ./test/lambdas/cpp.sh

Cite

If you would like to cite this work in another publication, please use the following citation.

Zenodo

[1]C. Spyridakis, A. Aktypi, T. Kyriakakisand S. Ioannidis, “SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security”, Oct. 2024. doi: 10.5281/zenodo.13986642.

IEEE Xplore

@INPROCEEDINGS{10679349,
author={Spyridakis, Christos and Aktypi, Angeliki and Kyriakakis, Thomas and Ioannidis, Sotiris},
booktitle={2024 IEEE International Conference on Cyber Security and Resilience (CSR)}, title={SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security}, year={2024},
volume={},
number={},
pages={827-832},
keywords={Linux;Containers;Software;Silicon;Libraries;Complexity theory;Security;Security;TEE;Intel SGX;SCONE},
doi={10.1109/CSR61664.2024.10679349}}

Funding & Support

This project has received funding from the European Health and Digital Executive Agency (HADEA) program under Grant Agreement No 101092950 (EDGELESS project) and support from the SCONTAIN team.

About

SecureExecutor is a tool to run code inside SGX enclaves

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

SecureExecutor

$SecureExecutor$ is a utility that automatically builds and runs SCONE containers.

These containers wrap C++/Python/Rust applications and are designed to run within SGX enclaves to leverage Trusted Execution Environment (TEE) functionality.

The ultimate goal of $SecureExecutor$ is to automate the process of running applications in enclaves. To achieve this, the utility was initially designed to collect minimal computational units, known as lambda functions, to build trusted images capable of leveraging TEEs. Following this, research activities are conducted to extend this functionality to a broader range of existing applications.

For this tool, the Community/Evaluation edition of SCONE is used, providing services that run inside enclaves in prerelease mode. For this reason, before using the tool, first create an account and login in its registry.

Usage

$SecureExecutor$ can take a large number of different input parameters. Just to name a few of them:

Usage: ./SecureExecutor [Option]... [Option]... Usage: ./SecureExecutor --lambda --function-name hello [--cpp/--rust/--python] [--new/--build/--run/--clean] Usage: ./SecureExecutor --app --path Dockerfiles/apps/steganography.Dockerfile [--build/--run] Usage: ./SecureExecutor --edgeless-node [--build/--run] Usage: ./SecureExecutor --edgeless-function --function-name hello [--rust/--python] [--new/--build] Options: -b, --build Use this flag to build the target image from the given function -c, --clean Clean the generated image (this requires to give the functionfunction name you want to clean) -d, --dynamic In case you want to dynamically link your executable use this flag (only for--lambdain --cpp, this produces smaller in size images TBI) -e, --env-var var You can use this, to pass multiple ENV vars during 'docker run ..' -f, --function-name functionSelect the name of the functionyou want to build or run (requires --lambda/--edgeless-function) -g, --tag tag_name If you want to provide an optional tag for your image, do it using this flag -h, --help Print this help menu and exit -n, --new Use this flag if you want to create a new lambda function -p, --path Use this flag to specify the path to the Dockerfile you want to use (requires --app) -r, --run Pass this flag to run a container -s, --static In case you want to statically link your executable use this flag (only for--lambdain --cpp, this produces larger in size images, default operation) -v, --volume absolute_path If you want to bind mound a directory use this option (MUST provide an absolute path) --lambda Use this to build a lambda function --app Use this to build from a Dockerfile --edgeless-node Use the edgeless node as target --edgeless-function Use this to build an edgeless-function --cpp Use a cpp functionas target (requires --lambda) --python Use a python functionas target (requires --lambda/--edgeless-function) --rust Use a rust functionas target (requires --lambda/--edgeless-function) 

Project Tree Explanation

.
├── doc # Extra documentation files for the repository
├── Dockerfiles # Dockerfiles for base images, applications, and lambda functions
├── LAS # Initial scripts for Local Attestation
├── scripts # Auxiliary scripts to simplify tasks
├── src # Source code for SecureExecutor
├── sysinfo # Modified Sysinfo Rust crate code (see sysinfo problem related to EDGELESS)
├── sysinfo_untrusted # Untrusted portion of sysinfo sources
├── templates # Templates for creating target lambda functions
├── test# Test scripts
├── SecureExecutor # Core of SecureExecutor (main function)
└── README.md # This documentation file

Lambdas

To understand how to create and run a lambda function, please read this file.

Applications

For more information regarding the applications that $SecureExecutor$ has been tested on so far, please refer to this file.

Demos

  • EDGELESS: This demo video showcases the creation of the trusted binary for the EDGELESS node using $SecureExecutor$, followed by the execution of a function on the node within the EDGELESS platform.

Dependencies

  • A Linux based machine with Intel SGX capabilities (developed/tested on a NUC device that runs Ubuntu 22.04). Read this if you want to know how to setup a system that is ready to run this tool.

  • Docker

curl -fsSL https://get.docker.com -o get-docker.sh
sudo sh get-docker.sh
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh

Known issues

  • Attestation: To ensure end-to-end secure execution, the appropriate attestation mechanisms have yet to be integrated into the current system.

    See SCONE CAS, LAS and Initial LAS experiments in this repository.

  • Encryption during transfer: To ensure end-to-end secure execution, encryption should also be enabled during the transmission of data from the client to the enclave.

  • Evaluate the system while running different workflows that contain diverse functions. Read EDGELESS examples tested section to gain more information.

Publication

Zenodo | IEEE Xplore

The following publication: "SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security" explains the high-level purpose of this tool and provides additional information about its internal behavior. Hence, it serves as a good starting point for understanding the tool’s internals. A pre-print version, is also available here.

Tests

This repository also includes an automated unit test mechanism. In the test/ directory, the run_tests.sh file is available to execute all tests.

./test/run_tests.sh

Test files exist in the respective folders in the test/ directory. If you want to run only for a specific case tests, then pass as an input argument the relative path.

# Syntax: ./test/run_tests.sh <file1_path> <file2_path> ...
./test/run_tests.sh ./test/lambdas/cpp.sh

Cite

If you would like to cite this work in another publication, please use the following citation.

Zenodo

[1]C. Spyridakis, A. Aktypi, T. Kyriakakisand S. Ioannidis, “SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security”, Oct. 2024. doi: 10.5281/zenodo.13986642.

IEEE Xplore

@INPROCEEDINGS{10679349,
author={Spyridakis, Christos and Aktypi, Angeliki and Kyriakakis, Thomas and Ioannidis, Sotiris},
booktitle={2024 IEEE International Conference on Cyber Security and Resilience (CSR)}, title={SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security}, year={2024},
volume={},
number={},
pages={827-832},
keywords={Linux;Containers;Software;Silicon;Libraries;Complexity theory;Security;Security;TEE;Intel SGX;SCONE},
doi={10.1109/CSR61664.2024.10679349}}

Funding & Support

This project has received funding from the European Health and Digital Executive Agency (HADEA) program under Grant Agreement No 101092950 (EDGELESS project) and support from the SCONTAIN team.

About

SecureExecutor is a tool to run code inside SGX enclaves

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

SecureExecutor

$SecureExecutor$ is a utility that automatically builds and runs SCONE containers.

These containers wrap C++/Python/Rust applications and are designed to run within SGX enclaves to leverage Trusted Execution Environment (TEE) functionality.

The ultimate goal of $SecureExecutor$ is to automate the process of running applications in enclaves. To achieve this, the utility was initially designed to collect minimal computational units, known as lambda functions, to build trusted images capable of leveraging TEEs. Following this, research activities are conducted to extend this functionality to a broader range of existing applications.

For this tool, the Community/Evaluation edition of SCONE is used, providing services that run inside enclaves in prerelease mode. For this reason, before using the tool, first create an account and login in its registry.

Usage

$SecureExecutor$ can take a large number of different input parameters. Just to name a few of them:

Usage: ./SecureExecutor [Option]... [Option]... Usage: ./SecureExecutor --lambda --function-name hello [--cpp/--rust/--python] [--new/--build/--run/--clean] Usage: ./SecureExecutor --app --path Dockerfiles/apps/steganography.Dockerfile [--build/--run] Usage: ./SecureExecutor --edgeless-node [--build/--run] Usage: ./SecureExecutor --edgeless-function --function-name hello [--rust/--python] [--new/--build] Options: -b, --build Use this flag to build the target image from the given function -c, --clean Clean the generated image (this requires to give the functionfunction name you want to clean) -d, --dynamic In case you want to dynamically link your executable use this flag (only for--lambdain --cpp, this produces smaller in size images TBI) -e, --env-var var You can use this, to pass multiple ENV vars during 'docker run ..' -f, --function-name functionSelect the name of the functionyou want to build or run (requires --lambda/--edgeless-function) -g, --tag tag_name If you want to provide an optional tag for your image, do it using this flag -h, --help Print this help menu and exit -n, --new Use this flag if you want to create a new lambda function -p, --path Use this flag to specify the path to the Dockerfile you want to use (requires --app) -r, --run Pass this flag to run a container -s, --static In case you want to statically link your executable use this flag (only for--lambdain --cpp, this produces larger in size images, default operation) -v, --volume absolute_path If you want to bind mound a directory use this option (MUST provide an absolute path) --lambda Use this to build a lambda function --app Use this to build from a Dockerfile --edgeless-node Use the edgeless node as target --edgeless-function Use this to build an edgeless-function --cpp Use a cpp functionas target (requires --lambda) --python Use a python functionas target (requires --lambda/--edgeless-function) --rust Use a rust functionas target (requires --lambda/--edgeless-function) 

Project Tree Explanation

.
├── doc # Extra documentation files for the repository
├── Dockerfiles # Dockerfiles for base images, applications, and lambda functions
├── LAS # Initial scripts for Local Attestation
├── scripts # Auxiliary scripts to simplify tasks
├── src # Source code for SecureExecutor
├── sysinfo # Modified Sysinfo Rust crate code (see sysinfo problem related to EDGELESS)
├── sysinfo_untrusted # Untrusted portion of sysinfo sources
├── templates # Templates for creating target lambda functions
├── test# Test scripts
├── SecureExecutor # Core of SecureExecutor (main function)
└── README.md # This documentation file

Lambdas

To understand how to create and run a lambda function, please read this file.

Applications

For more information regarding the applications that $SecureExecutor$ has been tested on so far, please refer to this file.

Demos

  • EDGELESS: This demo video showcases the creation of the trusted binary for the EDGELESS node using $SecureExecutor$, followed by the execution of a function on the node within the EDGELESS platform.

Dependencies

  • A Linux based machine with Intel SGX capabilities (developed/tested on a NUC device that runs Ubuntu 22.04). Read this if you want to know how to setup a system that is ready to run this tool.

  • Docker

curl -fsSL https://get.docker.com -o get-docker.sh
sudo sh get-docker.sh
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh

Known issues

  • Attestation: To ensure end-to-end secure execution, the appropriate attestation mechanisms have yet to be integrated into the current system.

    See SCONE CAS, LAS and Initial LAS experiments in this repository.

  • Encryption during transfer: To ensure end-to-end secure execution, encryption should also be enabled during the transmission of data from the client to the enclave.

  • Evaluate the system while running different workflows that contain diverse functions. Read EDGELESS examples tested section to gain more information.

Publication

Zenodo | IEEE Xplore

The following publication: "SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security" explains the high-level purpose of this tool and provides additional information about its internal behavior. Hence, it serves as a good starting point for understanding the tool’s internals. A pre-print version, is also available here.

Tests

This repository also includes an automated unit test mechanism. In the test/ directory, the run_tests.sh file is available to execute all tests.

./test/run_tests.sh

Test files exist in the respective folders in the test/ directory. If you want to run only for a specific case tests, then pass as an input argument the relative path.

# Syntax: ./test/run_tests.sh <file1_path> <file2_path> ...
./test/run_tests.sh ./test/lambdas/cpp.sh

Cite

If you would like to cite this work in another publication, please use the following citation.

Zenodo

[1]C. Spyridakis, A. Aktypi, T. Kyriakakisand S. Ioannidis, “SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security”, Oct. 2024. doi: 10.5281/zenodo.13986642.

IEEE Xplore

@INPROCEEDINGS{10679349,
author={Spyridakis, Christos and Aktypi, Angeliki and Kyriakakis, Thomas and Ioannidis, Sotiris},
booktitle={2024 IEEE International Conference on Cyber Security and Resilience (CSR)}, title={SecureExecutor: An Automated Way to Leverage SCONE to Enhance Application Security}, year={2024},
volume={},
number={},
pages={827-832},
keywords={Linux;Containers;Software;Silicon;Libraries;Complexity theory;Security;Security;TEE;Intel SGX;SCONE},
doi={10.1109/CSR61664.2024.10679349}}

Funding & Support

This project has received funding from the European Health and Digital Executive Agency (HADEA) program under Grant Agreement No 101092950 (EDGELESS project) and support from the SCONTAIN team.

About

SecureExecutor is a tool to run code inside SGX enclaves

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages