Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Harshavardhan Unnibhavi

dblp:290/8217 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2024
0000-0003-0375-2235ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 3 · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer architecture, parallel and distributed computing, and storage systems
3 papers
Cloud and datacenter computing · 51% Reconfigurable computing and FPGAs · 34% Storage systems · 8%
Software engineering, system software, and programming languages
3 papers
Operating systems · 100%
Network and information security
2 papers
Hardware security and side channels · 59% Privacy and data protection · 41%
Databases, data mining, and information retrieval
1 paper
Query processing and optimization · 100%

Topics — the 11 heaviest of 12, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Operating systems › virtualization
i/o virtualization
0.812024
vFPIO: A Virtual I/O Abstraction for FPGA-accelerated I/O Devices · USENIX ATC 2024
Query processing and optimization
secure query processing
0.612022
Secure and Policy-Compliant Query Processing on Heterogeneous Computational Storage Architectures · SIGMOD Conference 2022
Cloud and datacenter computing › virtualization › lightweight virtualization
lightweight virtual machines
0.612022
VMSH: hypervisor-agnostic guest overlays for VMs · EuroSys 2022
Cloud and datacenter computing
virtualization
0.612022
VMSH: hypervisor-agnostic guest overlays for VMs · EuroSys 2022
Hardware security and side channels
trusted execution environments
0.512021
rkt-io: a direct I/O stack for shielded execution · EuroSys 2021
Privacy and data protection › privacy compliance
GDPR compliance
0.212022
Secure and Policy-Compliant Query Processing on Heterogeneous Computational Storage Architectures · SIGMOD Conference 2022
Privacy and data protection
policy compliance
0.212022
Secure and Policy-Compliant Query Processing on Heterogeneous Computational Storage Architectures · SIGMOD Conference 2022
Operating systems
virtualization
0.212022
VMSH: hypervisor-agnostic guest overlays for VMs · EuroSys 2022
Storage systems
computational storage
0.212022
Secure and Policy-Compliant Query Processing on Heterogeneous Computational Storage Architectures · SIGMOD Conference 2022
Memory systems › processing-in-memory
near-data processing
0.212022
Secure and Policy-Compliant Query Processing on Heterogeneous Computational Storage Architectures · SIGMOD Conference 2022
Operating systems › i/o › i/o subsystem
i/o stack
0.112021
rkt-io: a direct I/O stack for shielded execution · EuroSys 2021

Methods — techniques the papers use, named apart from their topics

trusted execution environment · 2.7Intel SGX · 1.7ARM TrustZone · 1.7file system image attachment · 1.1container-based isolation · 1.1direct i/o · 1.0
YearPublicationVenuePosition
2024 vFPIO: A Virtual I/O Abstraction for FPGA-accelerated I/O Devices
Jiyang Chen, Harshavardhan Unnibhavi, Atsushi Koshiba, Pramod Bhatotia
USENIX ATC2
2022 VMSH: hypervisor-agnostic guest overlays for VMs
abstract
Lightweight virtual machines (VMs) are prominently adopted for improved performance and dependability in cloud environments. To reduce boot up times and resource utilisation, they are usually "pre-baked" with only the minimal kernel and userland strictly required to run an application. This introduces a fundamental trade-off between the advantages of lightweight VMs and available services within a VM, usually leaning towards the former. We propose VMSH, a hypervisor-agnostic abstraction that enables on-demand attachment of services to a running VM---allowing developers to provide minimal, lightweight images without compromising their functionality. The additional applications are made available to the guest via a file system image. To ensure that the newly added services do not affect the original applications in the VM, VMSH uses lightweight isolation mechanisms based on containers. We evaluate VMSH on multiple KVM-based hypervisors and Linux LTS kernels and show that: (i) VMSH adds no overhead for the applications running in the VM, (ii) de-bloating images from the Docker registry can save up to 60% of their size on average, and (iii) VMSH enables cloud providers to offer services to customers, such as recovery shells, without interfering with their VM's execution.
Jörg Thalheim, Peter Okelmann, Harshavardhan Unnibhavi, Redha Gouicem, Pramod Bhatotia
EuroSys3
2022 Secure and Policy-Compliant Query Processing on Heterogeneous Computational Storage Architectures
abstract
Computation Storage Architectures (CSA) are increasingly adopted in the cloud for near data processing, where the underlying storage devices/servers are now equipped with heterogeneous cores which enable computation offloading near to the data. While CSA is a promising high-performance architecture for the cloud, in general data analytics also presents significant data security and policy compliance (e.g., GDPR) challenges in untrusted cloud environments. In this paper, we present IronSafe, a secure and policy-compliant query processing system for heterogeneous computational storage architectures, while preserving the performance advantages of CSA in untrusted cloud environments. To achieve these design properties in a computing environment with heterogeneous host (x86) and storage system (ARM), we design and implement the entire hardware and software system stack from the ground-up leveraging hardware-assisted Trusted Execution Environments (TEEs): namely, Intel SGX and ARM TrustZone. More specifically, IronSafe builds on three core contributions: (1) a heterogeneous confidential computing framework for shielded execution with x86 and ARM TEEs and associated secure storage system for the untrusted storage medium; (2) a policy compliance monitor to provide a unified service for attestation and policy compliance; and (3) a declarative policy language and associated interpreter for concisely specifying and efficiently evaluating a rich set of polices. Our evaluation using the TPC-H SQL benchmark queries and GDPR anti-pattern use-cases shows that IronSafe is faster, on average by 2.3x than a host-only secure system, while providing strong security and policy-compliance properties.
Harshavardhan Unnibhavi, David Cerdeira, Antonio Barbalace, Nuno Santos 0001, Pramod Bhatotia
SIGMOD Conference1
2021 rkt-io: a direct I/O stack for shielded execution
abstract
The shielding of applications using trusted execution environments (TEEs) can provide strong security guarantees in untrusted cloud environments. When executing I/O operations, today's shielded execution frameworks, however, exhibit performance and security limitations: they assign resources to the I/O path inefficiently, perform redundant data copies, use untrusted host I/O stacks with security risks and performance overheads. This prevents TEEs from running modern I/O-intensive applications that require high-performance networking and storage.
Jörg Thalheim, Harshavardhan Unnibhavi, Christian Priebe, Pramod Bhatotia, Peter R. Pietzuch
EuroSys2