VLDB 2026 Research / reviewers in the wild / expert
Vasily A. Sartakov
dblp:151/4092
· DBLP profile ↗
9ranked-venue papers
9as first author
4since 2021 · last 2023
0000-0003-1894-2621ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 5 · 5 first-author · 3 since 2021Systems, architecture and hardware · 3 · 3 first-author · 2 since 2021Security and privacy · 3 · 3 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | ORC: Increasing Cloud Memory Density via Object Reuse with Capabilities
Vasily A. Sartakov, Lluís Vilanova, Munir Geden, David M. Eyers, Takahiro Shinagawa, Peter R. Pietzuch |
OSDI | 1 |
| 2022 | CAP-VMs: Capability-Based Isolation and Sharing in the Cloud
Vasily A. Sartakov, Lluís Vilanova, David M. Eyers, Takahiro Shinagawa, Peter R. Pietzuch |
OSDI | 1 |
| 2021 | CubicleOS: a library OS with software componentisation for practical isolationabstractLibrary OSs have been proposed to deploy applications isolated inside containers, VMs, or trusted execution environments. They often follow a highly modular design in which third-party components are combined to offer the OS functionality needed by an application, and they are customised at compilation and deployment time to fit application requirements. Yet their monolithic design lacks isolation across components: when applications and OS components contain security-sensitive data (e.g., cryptographic keys or user data), the lack of isolation renders library OSs open to security breaches via malicious or vulnerable third-party components. Vasily A. Sartakov, Lluís Vilanova, Peter R. Pietzuch |
ASPLOS | 1 |
| 2021 | Spons & Shields: practical isolation for trusted executionabstractTrusted execution environments (TEEs) promise a cost-effective, “lift-and-shift” solution for deploying security-sensitive applications in untrusted clouds. For this, they must support rich, multi-component applications, but a large trusted computing base (TCB) inside the TEE risks that attackers can compromise application security. Fine-grained compartmentalisation can increase security through defense-in-depth, but current solutions either run all software components unprotected in the same TEE, lack efficient shared memory support, or isolate application processes using separate TEEs, impacting performance and compatibility. Vasily A. Sartakov, Dan O'Keeffe, David M. Eyers, Lluís Vilanova, Peter R. Pietzuch |
VEE | 1 |
| 2018 | STANlite - A Database Engine for Secure Data Processing at Rack-Scale LevelabstractIntel's novel Software Guard eXtensions (SGX) enable secure and trusted execution of services, thereby paving the way to outsource sensitive data processing to external data centers. While SGX promises trusted execution close to native speed, frequent I/O operations and memory usage beyond a hardware-dependent threshold of currently 92 MiB result in substantial performance degradation. For memory-intensive workloads such as key-value stores and databases these penalties can be prohibitively high. We present STANlite - an in-memory database engine for SGX-enabled secure data processing in rack-scale environments. STANlite performs efficient user-level paging, whenever a database workload requires more space than the performance-friendly in-memory state size. Furthermore, STANlite smartly combines the properties of Remote Direct Memory Access (RDMA) and SGX to reduce the overhead of network-based I/O operations. While SGX usually provides confidentiality and integrity at the same time, STANlite enables a purely integrity preserving data management mode for additional performance. Finally, STANlite features a small trusted computing base and is memory-efficient, as it extends SQLite, a database for embedded use. We evaluated STANlite in terms of query response time. It outperforms a vanilla SGX-based SQLite version by 1.79x for microbenchmarks and 2.44x for TPC-C. Vasily A. Sartakov, Nico Weichbrodt, Sebastian Krieter, Thomas Leich, Rüdiger Kapitza |
IC2E | 1 |
| 2018 | EActors: Fast and flexible trusted computing using SGXabstractNovel trusted execution support, as offered by Intel's Software Guard eXtensions (SGX), embeds seamlessly into user space applications by establishing regions of encrypted memory, called enclaves. Enclaves comprise code and data that is executed under special protection of the CPU and can only be accessed via an enclave defined interface. To facilitate the usability of this new system abstraction, Intel offers a software development kit (SGX SDK). While the SDK eases the use of SGX, it misses appropriate programming support for inter-enclave interaction, and demands to hardcode the exact use of trusted execution into applications, which restricts flexibility. Vasily A. Sartakov, Stefan Brenner, Sonia Ben Mokhtar, Sara Bouchenak, Gaël Thomas 0001, Rüdiger Kapitza |
Middleware | 1 |
| 2017 | Multi-site Synchronous VM Replication for Persistent Systems with Asymmetric Read/Write LatenciesabstractNovel non-volatile memory is considered as a future replacement for conventional main memory. While besides persistence non-volatile memory technologies promise higher storage density and lower power demand, they also possess an asymmetry between fast read and slow write access times. The latter can be in the order of 2x to even 20x. While persistent main memory per se asks for novel system software support, the asymmetry between read and write access times needs to be addressed for building efficient solutions. This paper addresses virtual machine replication for high availability when non-volatile memory is put in use. So far asynchronous VM replication that stops a virtual machine, performs a local copy of dirty pages, resumes the virtual machine, before the data is transferred to a back-up site, is the state of the art. In contrast, we propose a multi-site zero-copy synchronous VM replication, which utilizes Remote Direct Memory Access and is tolerant to different read/write latencies. We demonstrate that for future hardware settings synchronous VM replication provides a performance increase of up to 27% compared to current best practices. Vasily A. Sartakov, Rüdiger Kapitza |
PRDC | 1 |
| 2015 | Temporality a NVRAM-based Virtualization PlatformabstractPower failures in data centers and Cloud Computing infrastructures can cause loss of data and impact revenue. Existing best practice such as persistent logging and checkpointing add overhead during operation and increase recovery time. Other solutions like the use of an uninterruptable power supply incur additional costs and are maintenance-intensive. Novel persistent main memory, i.e. memory that retains stored data without an external source of power, firstly prevents data loss in case of a power outage, secondly reduces the time for a system reboot and thirdly enables to continue operation at full-speed after a recovery. Yet new architectures and programming models are required to utilize persistent main memory. We present Temporality a virtualization layer that runs virtual machines in persistent memory and offers virtual persistent memory. It can be used as a basis for future Cloud platforms to allow applications the utilization of persistent memory without any changes. It provides safety of volatile data, significantly decreases overall recovery time and prevents subsequent performance degradation. Vasily A. Sartakov, Arthur Martens, Rüdiger Kapitza |
SRDS | 1 |
| 2014 | NV-Hypervisor: Hypervisor-Based Persistence for Virtual MachinesabstractPower outages and subsequent recovery are major causes of service downtimes. This issue is amplified by the ongoing trend of steadily growing in-memory state of Internet-based services which increases the risk of data loss and extends recovery time. Protective measures against power outages, such as uninterruptible power supply are expensive, maintenance-intensive and often fragile. With the advent of non-volatile random-access memory (NVRAM) provided by commodity servers, there is a scalable, less costly and robust alternative to recover from power outages and other failures. However, as of today, off-the-shelf software is not ready for benefiting from NVRAM. We present NV-Hyper visor a lightweight hyper visor extension that transparently provides persistence for virtual machines. NV-Hyper visor paves the way for utilizing NVRAM in virtualized environments (i.e., infrastructure-as-a-service clouds) and protects stateful services such as key-value stores and databases from data loss and time-consuming recovery. Vasily A. Sartakov, Rüdiger Kapitza |
DSN | 1 |